🛎 Cisco Umbrella : Notification on Security Events (Umbrella-Notification-Security-Events)
Receive a near real time notification in Webex Teams or via Email on a new domain blobked by Umbrella
This workflow can be trigger by a schedule to execute every X minutes
Use Case and Installations : Detailed informations about the workflow can be found HERE
🔦 Hunt - Search User
Search for a given user via :
Notify in Cisco Webex or/and via Email about result
Create Casebook if user found
Use Case and Installation : Detailed informations about the workflow can be found HERE
🧽 Cisco Secure EP - Remove Inactive Endpoints
Cisco Seucre Endpoint : Identify and Remove from computers list endpoints with a last seen over a given number of days (default : 45 days)
Include 2-Tiers approval and Notification in Cisco Webex
Use Case and Installation : Detailed informations about the workflow can be found HERE
TG-Feeds-to-Umbrella-BlockList-2-Tiers-approval
Download Threat Grid Curated feed and push domain to Cisco Umbrella Destinations Lists.
Include 2-Tiers approval and Notification in Cisco Webex
Use Case and Installation : Detailed informations about the workflow can be found HERE
🛎 RT-Monitoring-SecureEP-Umbrella-Notification-Incident
Continuous monitoring of Umbrella and/or Secure EP Security events (loop)
Near real time Incident creation and update (grouped by endpoint hostname, no duplicate event)
Near real time notification on new or updated incident (no duplicate notification for same event occurring multiple times)
Statistic tables
Use Case and Installations : Detailed informations about the workflow can be found HERE
NOTE: This is sample code and needs to be tested properly before using in production!
Periodically check for TG Feed and push domains to Umbrella destinations block list with 2-Tiers approval and notification

Logon to SecureX via: https://sign-on.security.cisco.com/.
NOTE: If you don't have a SecureX Account, please follow the Quick Start Guide.
Go to Menu "Orchestration"

Set up or Verify Targets, Account Keys and Variables
Go to "Account Keys" and create the following account. If it already exists under a different name, use it in step step for "Umbrella target"
Cisco Umbrella Management API - Account Keys from your Umbrella console
Go to "Targets" and create the following accounts. If they already exists under a different display name and you can't rename or duplicate them, you will have to modify Target Criteria in the workflow.
Cisco Umbrella Management API - Target
Cisco Secure Malware Analytics (Threat Grid)
Cisco Webex
Private CTIA (should already exists)
Go to Variables and Create or verify global variables for your TG API and Webex Token
TG_API
Webex Token
Go to Variables and verify settings (email) for Task Requestor and Task Approver
Go to Workflows select "Atomic Actions" and IMPORT Atomoc Actions

Import the following from Git SX-AO-AtomicActions

Import the following from Git Cisco Security/Atomics
Go to Workflows and IMPORT the following workflow from SX-AO
Adjust following variables to fit with your needs*
Detection_List_name set to the name of the Umbrella Destinations list to update
Umbrella_Org_ID set to Your Umbrella Org ID got from Umbrella console URL
Webex Room set to the Webex room name used for notification. Remember to add you BOT to this room
TG Feed Name set to one of the following :

8. Validate and test the workflow (run)

Ivan Berlinson (Cisco) - ivberlin@cisco.com
Code Exchange Community
Get help, share code, and collaborate with other developers in the Code Exchange community.View Community