API Credentials

The secret keys required by each secret are listed below.

Secret NameRequired KeysOptional Keys
abuseipdbABUSEIPDB_API_KEY-
alienvaultOTX_API_KEY-
ansible-ANSIBLE_PASSWORDS ANSIBLE_SSH_KEY
aws-AWS_ACCESS_KEY_ID AWS_PROFILE_NAME AWS_REGION AWS_ROLE_ARN AWS_ROLE_SESSION_NAME AWS_SECRET_ACCESS_KEY
censysCENSYS_API_KEY-
checkpointCHECKPOINT_ACCESS_KEY CHECKPOINT_AUTH_URL CHECKPOINT_CLIENT_ID-
crowdsec_ctiCTI_API_KEY-
crowdsecCROWDSEC_API_TOKEN-
crowdsecCROWDSEC_API_TOKEN CROWDSEC_API_URL-
crowdstrikeCROWDSTRIKE_CLIENT_ID CROWDSTRIKE_CLIENT_SECRET-
datadogDATADOG_API_KEY DATADOG_API_URL DATADOG_APP_KEY-
elasticELASTIC_API_KEY ELASTIC_API_URL-
emailrepEMAILREP_API_KEY-
google_apiGOOGLE_API_CREDENTIALS-
google_secops_soarAPI_TOKEN-
hybrid_analysisHYBRID_ANALYSIS_API_KEY-
jira-JIRA_API_TOKEN JIRA_BASE64_TOKEN JIRA_USEREMAIL
ldapLDAP_HOST LDAP_PASSWORD LDAP_PORT LDAP_USER-
limacharlieLIMACHARLIE_SECRET LIMACHARLIE_UIDLIMACHARLIE_OID
llm-OPENAI_API_KEY
malwarebazaarMALWAREBAZAAR_API_KEY-
microsoft_graphMICROSOFT_GRAPH_CLIENT_ID MICROSOFT_GRAPH_CLIENT_SECRETMICROSOFT_GRAPH_SCOPES MICROSOFT_OIDC_AUTHORITY MICROSOFT_TOKEN_AUTHORITY
mongodbMONGODB_CONNECTION_STRING-
oktaOKTA_API_TOKEN OKTA_BASE_URL-
pulsedivePULSEDIVE_API_KEY-
s3-AWS_ACCESS_KEY_ID AWS_PROFILE_NAME AWS_REGION AWS_ROLE_ARN AWS_ROLE_SESSION_NAME AWS_SECRET_ACCESS_KEY
sentinel_oneSENTINEL_ONE_API_TOKEN SENTINEL_ONE_BASE_URL-
shodanSHODAN_API_KEY-
slackSLACK_BOT_TOKEN-
smtpSMTP_HOST SMTP_PASS SMTP_PORT SMTP_USER-
ssl-SSL_CLIENT_CERT SSL_CLIENT_KEY SSL_CLIENT_PASSWORD
velociraptor_sslCONFIGURATION-
virustotalVIRUSTOTAL_API_KEY-
wazuh_wuiWAZUH_WUI_PASSWORD WAZUH_WUI_URL WAZUH_WUI_USERNAME-
wazuhWAZUH_API_TOKEN WAZUH_API_URL-
wizWIZ_API_URL WIZ_AUTH_URL WIZ_CLIENT_ID WIZ_CLIENT_SECRET-

Core Actions

Note that the fully qualified namespace for each Core Action UDF is prefixed with core..

Sub-namespaceFunctionSecrets
coreai_actionllm
corehttp_requestssl
coresend_email_smtpsmtp
core.transformfilter-
core.transformreshape-
core.workflowexecute-

Integrations

Note that the fully qualified namespace for each Integration UDF is prefixed with integrations..

Sub-namespaceFunctionSecrets
integrations.abuseipdbsearch_ip_addressabuseipdb, ssl
integrations.alienvaultsearch_domainalienvault, ssl
integrations.alienvaultsearch_hostnamealienvault, ssl
integrations.alienvaultsearch_ip_addressalienvault, ssl
integrations.alienvaultsearch_malware_samplealienvault, ssl
integrations.ansiblerun_ansible_playbookansible
integrations.ansiblerun_playbook_from_s3s3, ansible
integrations.awscall_boto3_clientaws
integrations.awscall_boto3_paginatoraws
integrations.awslist_findingsaws, aws, aws
integrations.aws_s3download_objects3
integrations.aws_s3parse_uri-
integrations.censyssearch_ip_addresscensys, ssl
integrations.check_pointget_auth_tokencheckpoint
integrations.check_pointget_xdr_incidentscheckpoint, ssl
integrations.check_pointupdate_xdr_incidentcheckpoint, ssl
integrations.crowdsecblock_ip_addresscrowdsec, ssl
integrations.crowdsecsearch_ip_addresscrowdsec_cti, ssl
integrations.crowdsecunblock_ip_addresscrowdsec, ssl
integrations.crowdstrikecall_falconpy_commandcrowdstrike
integrations.crowdstrikeget_cs_detectscrowdstrike, crowdstrike
integrations.crowdstrikeget_cs_incidentscrowdstrike, crowdstrike
integrations.crowdstrikeget_detect_summariescrowdstrike
integrations.crowdstrikelist_alertscrowdstrike
integrations.crowdstrikelist_detectscrowdstrike
integrations.crowdstrikelist_incident_summariescrowdstrike
integrations.crowdstrikelist_incidentscrowdstrike
integrations.crowdstrikeupdate_alert_statuscrowdstrike
integrations.crowdstrikeupdate_detect_statuscrowdstrike
integrations.datadogaggregate_eventsdatadog, ssl
integrations.datadoglist_alertsdatadog, ssl
integrations.elasticlist_alertselastic, ssl
integrations.elasticupdate_alert_statuselastic, ssl
integrations.elasticupdate_alert_status_by_idselastic, ssl
integrations.emailrepreport_emailemailrep, ssl
integrations.emailrepsearch_emailemailrep, ssl
integrations.google_apiget_auth_tokengoogle_api
integrations.google_secopslist_cases_by_titlegoogle_secops_soar, ssl
integrations.google_secopslist_detections_by_rule_idgoogle_api, ssl
integrations.hybrid_analysissearch_malware_samplehybrid_analysis, ssl
integrations.jiracreate_issuejira, ssl
integrations.jiraupdate_issuejira, ssl
integrations.ldapadd_entryldap
integrations.ldapdelete_entryldap
integrations.ldapdisable_active_directory_userldap
integrations.ldapenable_active_directory_userldap
integrations.ldapexpire_active_directory_userldap
integrations.ldapexpire_userldap
integrations.ldapfind_active_directory_usersldap
integrations.ldapfind_usersldap
integrations.ldapmodify_entryldap
integrations.ldapsearch_entriesldap
integrations.limacharlieget_auth_tokenlimacharlie
integrations.malwarebazaarsearch_malware_samplemalwarebazaar, ssl
integrations.microsoft_graphget_auth_tokenmicrosoft_graph
integrations.mongodbget_documentmongodb
integrations.mongodblist_documentsmongodb
integrations.mongodbperform_mongodb_crudmongodb
integrations.oktaexpire_sessionsokta, ssl
integrations.oktafind_usersokta, ssl
integrations.oktalist_user_eventsokta, ssl
integrations.oktasuspend_userokta, ssl
integrations.oktaunsuspend_userokta, ssl
integrations.pulsedivesearch_iocpulsedive, ssl
integrations.sentinel_oneget_agents_by_hostnamesentinel_one, ssl
integrations.sentinel_oneget_agents_by_hostname_exactsentinel_one, ssl
integrations.sentinel_oneget_agents_by_usernamesentinel_one, ssl
integrations.sentinel_oneget_agents_by_username_exactsentinel_one, ssl
integrations.sentinel_oneget_firewall_rulessentinel_one, ssl
integrations.sentinel_oneisolate_agentssentinel_one, ssl
integrations.sentinel_onelist_alertssentinel_one, ssl
integrations.sentinel_oneunisolate_agentssentinel_one, ssl
integrations.sentinel_oneupdate_alert_statussentinel_one, ssl
integrations.sentinel_oneupdate_firewall_rulesentinel_one, ssl
integrations.shodansearch_ip_addressshodan, ssl
integrations.slackcall_paginated_slack_apislack
integrations.slackcall_slack_apislack
integrations.slacklist_conversationsslack
integrations.slacklist_usersslack
integrations.slacklookup_userslack
integrations.slackpost_messageslack
integrations.velociraptorrun_velociraptor_queryvelociraptor_ssl
integrations.virustotallist_commentsvirustotal, ssl
integrations.virustotalsearch_ip_addressvirustotal, ssl
integrations.virustotalsearch_malware_samplevirustotal, ssl
integrations.virustotalsearch_urlvirustotal, ssl
integrations.wazuhclear_rootcheckwazuh, ssl
integrations.wazuhgenerate_wazuh_wui_tokenwazuh_wui, ssl
integrations.wazuhget_last_rootcheck_scanwazuh, ssl
integrations.wazuhget_results_rootcheckwazuh, ssl
integrations.wazuhrun_rootcheckwazuh, ssl
integrations.wazuhupdate_wazuh_agentswazuh, ssl, ssl, ssl
integrations.wizget_auth_tokenwiz

ETL Actions

Note that the fully qualified namespace for each ETL UDF is prefixed with etl..

Sub-namespaceFunctionSecrets
etl.extractionextract_emails-
etl.extractionextract_ipv4_addresses-
etl.extractionextract_urls-