Core Actions

Core action namespaces are prefixed with core..

NamespaceFunctionSecrets
coreai_actionllm
corehttp_pollssl
corehttp_requestssl
corerequire-
coresend_email_smtpsmtp
core.tableinsert_row-
core.tablelookup-
core.transformapply-
core.transformdeduplicate-
core.transformfilter-
core.transformis_in-
core.transformmap-
core.transformnot_in-
core.transformreshape-
core.workflowexecute-

Integrations

Integration namespaces are prefixed with tools..

NamespaceFunctionSecrets
tools.ansiblerun_playbookansible
tools.aws_boto3call_apiaws
tools.aws_boto3call_paginated_apiaws
tools.aws_s3download_objectaws_s3
tools.aws_s3parse_uriaws_s3
tools.check_point_infinityget_access_tokencheck_point_infinity
tools.crowdseclookup_ip_addresscrowdsec_cti, ssl
tools.crowdstrikelist_alertscrowdstrike
tools.crowdstrikelist_casescrowdstrike
tools.crowdstrikelist_detectscrowdstrike
tools.datadoglist_security_signalsdatadog, ssl
tools.elastic_securitylist_detection_signalselastic_security, ssl
tools.falconpycall_commandcrowdstrike
tools.google_apiget_access_tokengoogle_api
tools.ipinfolookup_ip_addressipinfo, ssl
tools.jamfget_access_tokenjamf
tools.jamflist_computersjamf, ssl
tools.jamflock_devicejamf, ssl
tools.jiracreate_issuejira, ssl
tools.jiraget_fieldsjira, ssl
tools.jiraget_prioritiesjira, ssl
tools.jiraget_priority_schemesjira, ssl
tools.jiraget_projectsjira, ssl
tools.ldapadd_entryldap
tools.ldapdelete_entryldap
tools.ldapmodify_entryldap
tools.ldapsearch_entriesldap
tools.microsoft_graphget_access_tokenmicrosoft_graph
tools.oktalookup_user_by_emailokta, ssl
tools.oktarevoke_sessionsokta, ssl
tools.pymongoexecute_operationmongodb
tools.pytenablecall_apitenable_nessus
tools.sentinel_onelist_threatssentinel_one, ssl
tools.slackask_text_inputslack
tools.slacklookup_user_by_emailslack
tools.slackpost_notificationslack
tools.slackpost_todoslack
tools.slackpost_updateslack
tools.slackrevoke_sessionsslack
tools.slack_blocksformat_choices-
tools.slack_blocksformat_links-
tools.slack_blocksformat_metadata-
tools.slack_blocksformat_metadata_context-
tools.slack_blocksformat_text_input-
tools.slack_elementsformat_overflow_menu-
tools.slack_sdkcall_methodslack
tools.slack_sdkcall_paginated_methodslack
tools.threatstreamlookup_domainssl, threatstream
tools.threatstreamlookup_emailssl, threatstream
tools.threatstreamlookup_file_hashssl, threatstream
tools.threatstreamlookup_ip_addressssl, threatstream
tools.threatstreamlookup_urlssl, threatstream
tools.urlscanlookup_urlssl, urlscan
tools.virustotallookup_domainssl, virustotal
tools.virustotallookup_file_hashssl, virustotal
tools.virustotallookup_ip_addressssl, virustotal
tools.virustotallookup_urlssl, virustotal
tools.wizget_access_tokenwiz

Credentials

Tracecat uses secret keys associated with each integration for 3rd-party authentication. Find out more about how secrets work in Tracecat here.

Secret NameRequired KeysOptional Keys
ansibleANSIBLE_SSH_KEYANSIBLE_PASSWORDS
aws_s3-AWS_ACCESS_KEY_ID AWS_PROFILE_NAME AWS_REGION AWS_ROLE_ARN AWS_ROLE_SESSION_NAME AWS_SECRET_ACCESS_KEY
aws-AWS_ACCESS_KEY_ID AWS_PROFILE_NAME AWS_REGION AWS_ROLE_ARN AWS_ROLE_SESSION_NAME AWS_SECRET_ACCESS_KEY
check_point_infinityCHECKPOINT_ACCESS_KEY CHECKPOINT_CLIENT_ID-
crowdsec_ctiCTI_API_KEY-
crowdstrikeCROWDSTRIKE_CLIENT_ID CROWDSTRIKE_CLIENT_SECRET-
datadogDATADOG_API_KEY DATADOG_APP_KEY-
elastic_securityELASTIC_API_KEY-
google_apiGOOGLE_API_CREDENTIALS-
ipinfoIPINFO_API_TOKEN-
jamfJAMF_CLIENT_ID JAMF_CLIENT_SECRET-
jiraJIRA_API_TOKEN JIRA_USEREMAIL-
ldapLDAP_HOST LDAP_PASSWORD LDAP_PORT LDAP_USER-
llm-OPENAI_API_KEY
microsoft_graphMICROSOFT_GRAPH_CLIENT_ID MICROSOFT_GRAPH_CLIENT_SECRET-
mongodbMONGODB_CONNECTION_STRING-
oktaOKTA_API_TOKEN-
sentinel_oneSENTINEL_ONE_API_TOKEN-
slackSLACK_BOT_TOKEN-
smtpSMTP_HOST SMTP_PASS SMTP_PORT SMTP_USER-
ssl-SSL_CLIENT_CERT SSL_CLIENT_KEY SSL_CLIENT_PASSWORD
tenable_nessusTENABLE_ACCESS_KEY TENABLE_SECRET_KEY-
threatstreamANOMALI_API_KEY ANOMALI_USERNAME-
urlscanURLSCAN_API_KEY-
virustotalVIRUSTOTAL_API_KEY-
wizWIZ_CLIENT_ID WIZ_CLIENT_SECRET-

Was this page helpful?