Protectwise
Protectwise provides Cloud-Powered Network Detection & Response (NDR).
Connect Protectwise with Devo SOAR
Navigate to Automations > Integrations.
Search for Protectwise.
Click Details, then the + icon. Enter the required information in the following fields.
Label: Enter a connection name.
Reference Values: Define variables here to templatize integration connections and actions. For example, you can use https://www.{{hostname}}.com where, hostname is a variable defined in this input. For more information on how to add data, see 'Add Data' Input Type for Integrations.
Verify SSL: Select option to verify connecting server's SSL certificate (Default is Verify SSL Certificate).
Remote Agent: Run this integration using the Devo SOAR Remote Agent.
Email: The Email for your Protectwise account.
Password: Your Protectwise password.
After you've entered all the details, click Connect.
Actions for Protectwise
Inspect IP
Retrieves the report associated to an IP address.
Input Field
Choose a connection that you have previously created and then fill in the necessary information in the following input fields to complete the connection.
Input Name | Description | Required |
---|---|---|
IP Column name | Name of the column with the IPs to inspect. | Required |
Start Time Column name | Name of the column with the beginning of the timerange to consider. | Required |
End Time Column name | Name of the column with the end of the timerange to consider. | Required |
Inspect Host
Retrieves the report associated to a host.
Input Field
Choose a connection that you have previously created and then fill in the necessary information in the following input fields to complete the connection.
Input Name | Description | Required |
---|---|---|
Host Column name | Name of the column with the hosts to inspect. | Required |
Start Time Column name | Name of the column with the beginning of the timerange to consider. | Required |
End Time Column name: | Name of the column with the end of the timerange to consider. | Required |
Search by File Hash
Retrieves metadata associated to a file hash.
Input Field
Choose a connection that you have previously created and then fill in the necessary information in the following input fields to complete the connection.
Input Name | Description | Required |
---|---|---|
Hash Column name | Name of the column with the hashes to inspect. | Required |
Start Time Column name | Name of the column with the beginning of the timerange to consider. | Required |
End Time Column name | Name of the column with the end of the timerange to consider. | Required |
Release Notes
v3.0.0
- Updated architecture to support IO via filesystemv2.0.1
- Added documentation link in the automation library.