API Credentials

The secret keys required by each secret are listed below.

Secret NameRequired KeysOptional Keys
abuseipdbABUSEIPDB_API_KEY-
alienvaultOTX_API_KEY-
awsAWS_ACCESS_KEY_ID AWS_REGION AWS_SECRET_ACCESS_KEY-
censysCENSYS_API_KEY-
checkpointCHECKPOINT_ACCESS_KEY CHECKPOINT_API_URL CHECKPOINT_AUTH_URL CHECKPOINT_CLIENT_ID-
crowdsecCROWDSEC_API_KEY-
crowdsecCROWDSEC_API_TOKEN-
crowdstrikeCROWDSTRIKE_CLIENT_ID CROWDSTRIKE_CLIENT_SECRET-
datadogDATADOG_API_KEY DATADOG_APP_KEY-
elasticELASTIC_API_KEY ELASTIC_API_URL-
emailrepEMAILREP_API_KEY-
hybrid_analysisHYBRID_ANALYSIS_API_KEY-
jira-JIRA_API_TOKEN JIRA_BASE64_TOKEN JIRA_USEREMAIL
ldapLDAP_BIND_DN LDAP_BIND_PASS LDAP_HOST LDAP_PORT-
limacharlieLIMACHARLIE_SECRET LIMACHARLIE_UIDLIMACHARLIE_OID
llm-OPENAI_API_KEY
malwarebazaarMALWAREBAZAAR_API_KEY-
microsoft_graphMICROSOFT_GRAPH_CLIENT_ID MICROSOFT_GRAPH_CLIENT_SECRET MICROSOFT_GRAPH_TENANT_IDMICROSOFT_GRAPH_SCOPE
mongodbMONGODB_CONNECTION_STRING-
oktaOKTA_API_TOKEN OKTA_BASE_URL-
pulsedivePULSEDIVE_API_KEY-
sentinel_oneSENTINEL_ONE_API_TOKEN SENTINEL_ONE_BASE_URL-
shodanSHODAN_API_KEY-
slackSLACK_BOT_TOKEN-
virustotalVIRUSTOTAL_API_KEY-
wizWIZ_API_URL WIZ_AUTH_URL WIZ_CLIENT_ID WIZ_CLIENT_SECRET-

Core Actions

Note that the fully qualified namespace for each Core Action UDF is prefixed with core..

Sub-namespaceFunctionSecrets
coreai_actionllm
corehttp_request-
coresend_email_smtp-
core.transformbuild_reference_table-
core.transformfilter-
core.transformreshape-
core.workflowexecute-

Integrations

Note that the fully qualified namespace for each Integration UDF is prefixed with integrations..

Sub-namespaceFunctionSecrets
integrations.abuseipdbsearch_ip_addressabuseipdb
integrations.alienvaultsearch_domainalienvault
integrations.alienvaultsearch_hostnamealienvault
integrations.alienvaultsearch_ip_addressalienvault
integrations.alienvaultsearch_malware_samplealienvault
integrations.awscall_boto3_clientaws
integrations.awscall_boto3_paginatoraws
integrations.awslist_findingsaws, aws, aws
integrations.censyssearch_ip_addresscensys
integrations.checkpointget_auth_tokencheckpoint
integrations.crowdsecblock_ip_addresscrowdsec
integrations.crowdsecsearch_ip_addresscrowdsec
integrations.crowdsecunblock_ip_addresscrowdsec
integrations.crowdstrikecall_falconpy_commandcrowdstrike
integrations.crowdstrikeget_detect_summariescrowdstrike
integrations.crowdstrikelist_alertscrowdstrike
integrations.crowdstrikelist_detectscrowdstrike
integrations.crowdstrikeupdate_alert_statuscrowdstrike
integrations.crowdstrikeupdate_detect_statuscrowdstrike
integrations.datadoglist_alertsdatadog
integrations.elasticlist_alertselastic
integrations.elasticupdate_alert_statuselastic
integrations.elasticupdate_alert_status_by_idselastic
integrations.emailrepreport_emailemailrep
integrations.emailrepsearch_emailemailrep
integrations.hybrid_analysissearch_malware_samplehybrid_analysis
integrations.jiracreate_issuejira
integrations.jiraupdate_issuejira
integrations.ldapdisable_active_directory_userldap
integrations.ldapenable_active_directory_userldap
integrations.ldapfind_ldap_usersldap
integrations.limacharlieget_auth_tokenlimacharlie
integrations.malwarebazaarsearch_malware_samplemalwarebazaar
integrations.microsoft_graphget_auth_tokenmicrosoft_graph
integrations.mongodbget_documentmongodb
integrations.mongodblist_documentsmongodb
integrations.mongodbperform_mongodb_crudmongodb
integrations.oktaexpire_sessionsokta
integrations.oktafind_usersokta
integrations.oktalist_user_eventsokta
integrations.oktasuspend_userokta
integrations.oktaunsuspend_userokta
integrations.pulsedivesearch_iocpulsedive
integrations.sentinel_oneget_agents_by_hostnamesentinel_one
integrations.sentinel_oneget_agents_by_hostname_exactsentinel_one
integrations.sentinel_oneget_agents_by_usernamesentinel_one
integrations.sentinel_oneget_agents_by_username_exactsentinel_one
integrations.sentinel_oneget_firewall_rulessentinel_one
integrations.sentinel_oneisolate_agentssentinel_one
integrations.sentinel_onelist_alertssentinel_one
integrations.sentinel_oneunisolate_agentssentinel_one
integrations.sentinel_oneupdate_alert_statussentinel_one
integrations.sentinel_oneupdate_firewall_rulesentinel_one
integrations.shodansearch_ip_addressshodan
integrations.sinkswrite_to_database-
integrations.slackcall_paginated_slack_apislack
integrations.slackcall_slack_apislack
integrations.slacklist_conversationsslack
integrations.slacklist_usersslack
integrations.slackpost_messageslack
integrations.virustotalsearch_ip_addressvirustotal
integrations.virustotalsearch_malware_samplevirustotal
integrations.virustotalsearch_urlvirustotal
integrations.wizget_auth_tokenwiz

ETL Actions

Note that the fully qualified namespace for each ETL UDF is prefixed with etl..

Sub-namespaceFunctionSecrets
etl.extractionextract_emails-
etl.extractionextract_ipv4_addresses-
etl.extractionextract_urls-