API Credentials

The secret keys required by each secret are listed below.

Secret NameSecret Keys
aws_guarddutyAWS_ACCESS_KEY_ID, AWS_REGION, AWS_SECRET_ACCESS_KEY
microsoft_defender_endpointMICROSOFT_GRAPH_CLIENT_ID, MICROSOFT_GRAPH_CLIENT_SECRET, MICROSOFT_GRAPH_TENANT_ID
oktaOKTA_API_TOKEN, OKTA_BASE_URL
crowdstrikeCROWDSTRIKE_CLIENT_ID, CROWDSTRIKE_CLIENT_SECRET
slackSLACK_BOT_TOKEN
microsoft_defender_cloudMICROSOFT_GRAPH_CLIENT_ID, MICROSOFT_GRAPH_CLIENT_SECRET, MICROSOFT_GRAPH_TENANT_ID
datadogDD_API_KEY, DD_APP_KEY, DD_REGION
resend_api_keyRESEND_API_KEY
openaiOPENAI_API_KEY
virustotalVIRUSTOTAL_API_KEY
sentinel_oneSENTINEL_ONE_API_TOKEN, SENTINEL_ONE_BASE_URL
wizWIZ_API_URL, WIZ_AUTH_URL, WIZ_CLIENT_ID, WIZ_CLIENT_SECRET
elasticELASTIC_API_KEY, ELASTIC_API_URL
ldapLDAP_BIND_DN, LDAP_BIND_PASS

Core Actions

Note that the fully qualified namespace for each Core Action UDF is prefixed with core..

Sub-namespaceFunctionSecrets
-send_email_smtp-
-open_case-
conditionregex-
conditioncompare-
conditionmembership-
-http_request-
-ai_actionopenai
transformreshape-
transformfilter-
transformbuild_reference_table-
workflowexecute-

Integrations

Note that the fully qualified namespace for each Integration UDF is prefixed with integrations..

Sub-namespaceFunctionSecrets
aws.guarddutylist_guardduty_alertsaws_guardduty
microsoft_defenderlist_defender_cloud_alertsmicrosoft_defender_cloud
wizlist_wiz_alertswiz
chat.slackpost_slack_messageslack
chat.slacklist_slack_conversationsslack
chat.slacklist_slack_usersslack
chat.slacktag_slack_usersslack
crowdstrikelist_crowdstrike_alertscrowdstrike
crowdstrikelist_crowdstrike_detectscrowdstrike
crowdstrikeupdate_crowdstrike_alert_statuscrowdstrike
crowdstrikeupdate_crowdstrike_detect_statuscrowdstrike
microsoft_defenderlist_defender_endpoint_alertsmicrosoft_defender_endpoint
sentinel_onelist_sentinelone_alertssentinel_one
sentinel_oneupdate_sentinelone_alert_statussentinel_one
sentinel_oneget_sentinelone_agents_by_usernamesentinel_one
sentinel_oneget_sentinelone_agents_by_hostnamesentinel_one
sentinel_oneisolate_sentinelone_agentsentinel_one
sentinel_oneunisolate_sentinelone_agentsentinel_one
sentinel_oneget_sentinel_one_firewall_rulesentinel_one
sentinel_oneupdate_sentinel_one_firewall_rulesentinel_one
email.resendsend_email_resendresend_api_key
virustotalanalyze_urlvirustotal
virustotalanalyze_ip_addressvirustotal
virustotalanalyze_malware_samplevirustotal
ldapfind_ldap_usersldap
ldapdisable_ad_userldap
ldapenable_ad_userldap
oktafind_okta_usersokta
oktasuspend_okta_userokta
oktaunsuspend_okta_userokta
oktaexpire_okta_sessionsokta
oktalist_okta_user_eventsokta
datadoglist_datadog_alertsdatadog
elasticlist_elastic_alertselastic
sinkswrite_to_database-

ETL Actions

Note that the fully qualified namespace for each ETL UDF is prefixed with etl..

Sub-namespaceFunctionSecrets
extractionextract_emails-
extractionextract_ipv4_addresses-
extractionextract_urls-