Skip to main content

Gurucul-GRA

This Integration is part of the Gurucul Risk Analytics Pack.#

Supported versions

Available on Cortex XSOAR and Cortex XSIAM.

Gurucul Risk Analytics (GRA) is a data science backed cloud native platform that predicts, detects and prevents breaches. It ingests and analyzes massive amounts of data from the network, IT systems, cloud platforms, EDR, applications, IoT, HR and much more to give you a comprehensive contextual view of user and entity behaviors. This integration fetches GRA Incidents or Alerts into Cortex and exposes War Room commands for investigation and actions. Workflows can be configured in Cortex based on the commands provided by GRA.

Please make sure you look at the integration source code and comments.

Configure Gurucul in Cortex#

ParameterDescriptionRequired
Server URL (e.g. https://example.net)The GRA server URL.True
Authorization KeyThe API key used to authenticate to GRA.True
Fetch incidentsWhether this instance fetches incidents.False
Incident typeThe incident type to assign to fetched incidents.False
Trust any certificate (not secure)Whether to trust any certificate.False
Use system proxy settingsWhether to use the system proxy settings.False
First fetch timeThe first-fetch time window used only when no ID cursor exists yet.False
Maximum number of incidents per fetchThe maximum number of incidents to fetch per run.False
Fetch typeThe objects to import from GRA (Incidents or Alerts). Default: Incidents. Cases are no longer fetched. Use a separate instance for Alerts.False
GRA server timezoneSet the timezone of the GRA server (IANA id). Used when fetching Incidents and Alerts. Not used for First fetch time. Default UTC.False

Fetch setup (Incidents vs Alerts)#

Use two integration instances when you need both types:

InstanceFetch typeClassifierMapper (incoming)Incident type
IncidentsIncidents (YAML default)None / SelectGRAIncident-Mapper (YAML default)GRAIncident (YAML default)
AlertsAlertsNone / SelectGRAAlert-MapperGRAAlert

Important: Check Do not use by default on all Gurucul-GRA instances. If it is unchecked, Cortex can run War Room commands against this instance alongside all other enabled instances that are still use-by-default.

New instances default to Fetch type = Incidents, with Mapper (incoming) = GRAIncident-Mapper and Incident type = GRAIncident (YAML defaults). On an Alerts instance, set Fetch type to Alerts, then set Mapper and Incident type to the Alert values above so fields and layouts map correctly.

Set GRA server timezone to the GRA server timezone so Occurred matches GRA (default UTC). It is not used for First fetch time. War Room commands still return GRA date strings unchanged.

Upgrading from Case fetch (2.1.0)#

If you already run a Gurucul instance that fetched Cases, update carefully so fetch does not run with the wrong type/mapper mid-upgrade:

  1. Disable Fetches incidents on the existing Cases instance (or disable the instance).
  2. Update the Gurucul pack to 2.1.0 .
  3. Open the same instance and confirm or set:
    • Classifier = None / Select
    • Fetch type = Incidents (integration default; was not used for Cases fetch on older versions)
    • Mapper (incoming) = GRAIncident-Mapper (default on new instances)
    • Incident type = GRAIncident (default on new instances)
  4. Check Do not use by default checkbox.
  5. Save, then re-enable fetch.

Notes:

  • Existing GRACase incidents in Cortex remain; use gra-case-* commands for actions on them. Cases are no longer fetched.
  • If the instance last-run still has maxCaseId and no maxIncidentId, that Case cursor is reused as maxIncidentId so the first Incident fetch does not use the initial date window from First fetch time.
  • For Alerts, create a separate instance using the Alerts row in the table above.
  • GRA nomenclature: GRA now uses Data Source instead of Resource. Incident and Alert fields use Data Source. Deprecated Resource account commands remain; prefer the Data Source replacements. Existing GRACase incidents and Case commands keep Resource so they continue to work. The Alert field GRA Alert Resource is replaced by GRA Alert Data Source.

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

Important: Always specify the target instance on War Room commands by passing using="InstanceName", for example !gra-incidents status=OPEN using="Your-Incidents-instance". Without using, the command may not reach the intended Gurucul-GRA instance and can fail or return results from another instance.

gra-fetch-users#


Retrieve List of All Users (Identities)

Base Command#

gra-fetch-users

Input#

Argument NameDescriptionRequired
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Users.firstNameStringFirst Name.
Gra.Users.middleNameStringMiddle Name.
Gra.Users.lastNameStringLast Name.
Gra.Users.employeeIdStringEmployee Name.
Gra.Users.riskScoreStringRisk Name.
Gra.Users.departmentStringDepartment.
Gra.Users.emailStringUsers email.
Gra.Users.phoneStringUsers Phone no.
Gra.Users.locationStringLocation.
Gra.Users.managerStringUsers Manager.
Gra.Users.titleStringUsers title.
Gra.Users.joiningDateStringJoining Date.
Gra.Users.exitDateStringExit Date.
Gra.Users.userRiskStringUser Risk.
Gra.Users.profilePicturePathStringProfile Picture Path.

Command Example#

!gra-fetch-users page=1 max=25

Context Example#

[{
"firstName":"Evan",
"middleName":null,
"lastName":"Todd",
"employeeId":"Galvin.Chavez",
"riskScore":0,
"userRisk":0,
"department":"Legal Department",
"email":"non.magna@gurucul.corp",
"phone":"(598) 457-3271",
"location":"AK",
"manager":"Asher.Byers",
"title":"QA",
"joiningDate":"11/05/2018 05:27:51",
"exitDate":"08/25/2018 14:58:25",
"profilePicturePath":null
}]

Base Command#

gra-fetch-accounts


Retrieve all Accounts Information

Input#

Argument NameDescriptionRequired
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Accounts.idNumberAccount Id.
Gra.Accounts.nameStringAccount Name.
Gra.Accounts.typeStringAccount type.
Gra.Accounts.created_onDateCreated On.
Gra.Accounts.departmentStringDepartment.
Gra.Accounts.descriptionStringDescription.
Gra.Accounts.datasourcenameStringData Source Name.
Gra.Accounts.resourceStringResource. Deprecated. Use Gra.Accounts.datasourcename instead.
Gra.Accounts.domainStringDomain.
Gra.Accounts.high_riskStringHigh Risk.
Gra.Accounts.is_orphanStringIs Orphan.
Gra.Accounts.is_reassignedStringIs Reassigned.
Gra.Accounts.risk_scoreNumberRisk Score.
Gra.Accounts.updated_onDateUpdated on.

Command Example#

!gra-fetch-accounts page=1 max=25

Context Example#

[
{
"id":93,
"name":"Asher.Guthrie",
"type":null,
"created_on":"05/16/2019 06:49:18",
"department":null,
"description":null,
"datasourcename":"Windows Security",
"domain":"in",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":0,
"updated_on":null
}
]

Human Readable Output#

Results#

gra-fetch-active-resource-accounts#


Retrieve List of All Active Accounts for a Given Resource.

Deprecated. Use gra-fetch-active-datasource-accounts instead.

Base Command#

!gra-fetch-active-resource-accounts

Input#

Argument NameDescriptionRequired
resource_nameResource Name.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Active.Resource.Accounts.idNumberAccount Id.
Gra.Active.Resource.Accounts.nameStringAccount Name.
Gra.Active.Resource.Accounts.typeStringAccount type.
Gra.Active.Resource.Accounts.created_onDateCreated On.
Gra.Active.Resource.Accounts.departmentStringDepartment.
Gra.Active.Resource.Accounts.descriptionStringDescription.
Gra.Active.Resource.Accounts.resourceStringResource Name.
Gra.Active.Resource.Accounts.domainStringDomain.
Gra.Active.Resource.Accounts.high_riskStringHigh Risk.
Gra.Active.Resource.Accounts.is_orphanStringIs Orphan.
Gra.Active.Resource.Accounts.is_reassignedStringIs Reassigned.
Gra.Active.Resource.Accounts.risk_scoreNumberRisk Score.
Gra.Active.Resource.Accounts.updated_onDateUpdated on.

Command Example#

!gra-fetch-active-resource-accounts resource_name="Linux" page=1 max=25

Context Example#

[
{
"id":93,
"name":"Asher.Guthrie",
"type":null,
"created_on":"05/16/2019 06:49:18",
"department":null,
"description":null,
"resource":"Windows Security",
"domain":"in",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":0,
"updated_on":null
}
]

Human Readable Output#

gra-fetch-active-datasource-accounts#


Retrieve list of all active accounts for a specified data source.

Base Command#

gra-fetch-active-datasource-accounts

Input#

Argument NameDescriptionRequired
datasource_nameData Source Name.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Active.Datasource.Accounts.idNumberAccount Id.
Gra.Active.Datasource.Accounts.nameStringAccount Name.
Gra.Active.Datasource.Accounts.typeStringAccount type.
Gra.Active.Datasource.Accounts.created_onDateCreated On.
Gra.Active.Datasource.Accounts.departmentStringDepartment.
Gra.Active.Datasource.Accounts.descriptionStringDescription.
Gra.Active.Datasource.Accounts.datasourcenameStringData Source Name.
Gra.Active.Datasource.Accounts.domainStringDomain.
Gra.Active.Datasource.Accounts.high_riskStringHigh Risk.
Gra.Active.Datasource.Accounts.is_orphanStringIs Orphan.
Gra.Active.Datasource.Accounts.is_reassignedStringIs Reassigned.
Gra.Active.Datasource.Accounts.risk_scoreNumberRisk Score.
Gra.Active.Datasource.Accounts.updated_onDateUpdated on.

Command Example#

!gra-fetch-active-datasource-accounts datasource_name="Linux" page=1 max=25

Context Example#

[
{
"id":93,
"name":"Asher.Guthrie",
"type":null,
"created_on":"05/16/2019 06:49:18",
"department":null,
"description":null,
"datasourcename":"Windows Security",
"domain":"in",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":0,
"updated_on":null
}
]

Human Readable Output#

gra-fetch-user-accounts#


Retrieve List of All Active Accounts and Details for a Given User.

Base Command#

gra-fetch-user-accounts

Input#

Argument NameDescriptionRequired
employee_idEmployee ID.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.User.Accounts.idNumberUser Account Relation Id .
Gra.User.Accounts.nameStringAccount Name.
Gra.User.Accounts.typeStringAccount Type.
Gra.User.Accounts.created_onDateCreated On.
Gra.User.Accounts.departmentStringDepartment.
Gra.User.Accounts.descriptionStringDescription.
Gra.User.Accounts.datasourcenameStringData Source Name.
Gra.User.Accounts.resourceStringResource. Deprecated. Use Gra.User.Accounts.datasourcename instead.
Gra.User.Accounts.domainStringDomain Name.
Gra.User.Accounts.high_riskStringHigh Risk.
Gra.User.Accounts.is_orphanStringIs Account Orphan.
Gra.User.Accounts.is_reassignedStringIs account Reassigned.
Gra.User.Accounts.risk_scoreStringAccount Risk Score.
Gra.User.Accounts.updated_onDateUpdated On.

Command Example#

!gra-fetch-user-accounts employee_id="Alec.Holland01_NN" page=1 max=25

Context Example#

[{
"id":35,
"name":"Alec.Holland01_NN",
"type":null,
"created_on":"02/09/2018 10:00:00",
"department":null,
"description":null,
"datasourcename":"IPS",
"domain":"com",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":69,
"updated_on":null
}]

Human Readable Output#

gra-fetch-resource-highrisk-accounts#


Retrieve High Risk Accounts for a Given Resource

Deprecated. Use gra-fetch-datasource-highrisk-accounts instead.

Base Command#

gra-fetch-resource-highrisk-accounts

Input#

Argument NameDescriptionRequired
resource_nameResource Name.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Resource.Highrisk.Accounts.idNumberUser Account Relation Id .
Gra.Resource.Highrisk.Accounts.nameStringAccount Name.
Gra.Resource.Highrisk.Accounts.typeStringAccount Type.
Gra.Resource.Highrisk.Accounts.created_onDateCreated On.
Gra.Resource.Highrisk.Accounts.departmentStringDepartment.
Gra.Resource.Highrisk.Accounts.descriptionStringDescription.
Gra.Resource.Highrisk.Accounts.resourceStringResource Name.
Gra.Resource.Highrisk.Accounts.domainStringDomain Name.
Gra.Resource.Highrisk.Accounts.high_riskStringHigh Risk.
Gra.Resource.Highrisk.Accounts.is_orphanStringIs Account Orphan.
Gra.Resource.Highrisk.Accounts.is_reassignedStringIs account Reassigned.
Gra.Resource.Highrisk.Accounts.risk_scoreStringAccount Risk Score.
Gra.Resource.Highrisk.Accounts.updated_onDateUpdated On.

Command Example#

!gra-fetch-resource-highrisk-accounts resource_name="Windows Security" page=1 max=25

Context Example#

[{
"id":35,
"name":"Alec.Holland01_NN",
"type":null,
"created_on":"02/09/2018 10:00:00",
"department":null,
"description":null,
"resource":"Windows Security",
"domain":"com",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":69,
"updated_on":null
}]

Human Readable Output#

gra-fetch-hpa#


Retrieve List of All High Risk Privileged Accounts.

Base Command#

!gra-fetch-hpa

Input#

Argument NameDescriptionRequired
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Hpa.idNumberUser Account Relation Id .
Gra.Hpa.nameStringAccount Name.
Gra.Hpa.typeStringAccount Type.
Gra.Hpa.created_onDateCreated On.
Gra.Hpa.departmentStringDepartment.
Gra.Hpa.descriptionStringDescription.
Gra.Hpa.datasourcenameStringData Source Name.
Gra.Hpa.resourceStringResource. Deprecated. Use Gra.Hpa.datasourcename instead.
Gra.Hpa.domainStringDomain Name.
Gra.Hpa.high_riskStringHigh Risk.
Gra.Hpa.is_orphanStringIs Account Orphan.
Gra.Hpa.is_reassignedStringIs account Reassigned.
Gra.Hpa.risk_scoreStringAccount Risk Score.
Gra.Hpa.updated_onDateUpdated On.

Command Example#

!gra-fetch-hpa page=1 max=25

Context Example#

{
"id":35,
"name":"Alec.Holland01_NN",
"type":null,
"created_on":"02/09/2018 10:00:00",
"department":null,
"description":null,
"datasourcename":"IPS",
"domain":"com",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":69,
"updated_on":null
}

Human Readable Output#

#

gra-fetch-resource-hpa#


Retrieve all High Privileged Accounts for a Given Resource.

Deprecated. Use gra-fetch-datasource-hpa instead.

Base Command#

gra-fetch-resource-hpa

Input#

Argument NameDescriptionRequired
resource_nameResource Name.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Resource.Hpa.idNumberUser Account Relation Id .
Gra.Resource.Hpa.nameStringAccount Name.
Gra.Resource.Hpa.typeStringAccount Type.
Gra.Resource.Hpa.created_onDateCreated On.
Gra.Resource.Hpa.departmentStringDepartment.
Gra.Resource.Hpa.descriptionStringDescription.
Gra.Resource.Hpa.resourceStringResource Name.
Gra.Resource.Hpa.domainStringDomain Name.
Gra.Resource.Hpa.high_riskStringHigh Risk.
Gra.Resource.Hpa.is_orphanStringIs Account Orphan.
Gra.Resource.Hpa.is_reassignedStringIs account Reassigned.
Gra.Resource.Hpa.risk_scoreStringAccount Risk Score.
Gra.Resource.Hpa.updated_onDateUpdated On.

Command Example#

!gra-fetch-resource-hpa resource_name="Linux" page=1 max=25

Context Example#

[{
"id":2,
"name":"user1",
"type":null,
"created_on":"02/09/2017 10:00:00",
"department":null,
"description":null,
"resource":"Linux",
"domain":"com",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":0,
"updated_on":null
}]

Human Readable Output#

gra-fetch-orphan-accounts#


Retrieve List of All Orphan / Rogue Accounts.

Base Command#

gra-fetch-orphan-accounts

Input#

Argument NameDescriptionRequired
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Orphan.Accounts.idNumberUser Account Relation Id .
Gra.Orphan.Accounts.nameStringAccount Name.
Gra.Orphan.Accounts.typeStringAccount Type.
Gra.Orphan.Accounts.created_onDateCreated On.
Gra.Orphan.Accounts.departmentStringDepartment.
Gra.Orphan.Accounts.descriptionStringDescription.
Gra.Orphan.Accounts.datasourcenameStringData Source Name.
Gra.Orphan.Accounts.resourceStringResource. Deprecated. Use Gra.Orphan.Accounts.datasourcename instead.
Gra.Orphan.Accounts.domainStringDomain Name.
Gra.Orphan.Accounts.high_riskStringHigh Risk.
Gra.Orphan.Accounts.is_orphanStringIs Account Orphan.
Gra.Orphan.Accounts.is_reassignedStringIs account Reassigned.
Gra.Orphan.Accounts.risk_scoreStringAccount Risk Score.
Gra.Orphan.Accounts.updated_onDateUpdated On.

Command Example#

!gra-fetch-orphan-accounts page=1 max=25

Context Example#

[{
"id":2,
"name":"user1",
"type":null,
"created_on":"02/09/2017 10:00:00",
"department":null,
"description":null,
"datasourcename":"Linux",
"domain":"com",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":0,
"updated_on":null
}]

Human Readable Output#

gra-fetch-resource-orphan-accounts#


Retrieve All Orphan / Rogue Accounts for a Given Resource.

Deprecated. Use gra-fetch-datasource-orphan-accounts instead.

Base Command#

gra-fetch-resource-orphan-accounts

Input#

Argument NameDescriptionRequired
resource_nameResource Name.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Resource.Orphan.Accounts.idNumberUser Account Relation Id .
Gra.Resource.Orphan.Accounts.nameStringAccount Name.
Gra.Resource.Orphan.Accounts.typeStringAccount Type.
Gra.Resource.Orphan.Accounts.created_onDateCreated On.
Gra.Resource.Orphan.Accounts.departmentStringDepartment.
Gra.Resource.Orphan.Accounts.descriptionStringDescription.
Gra.Resource.Orphan.Accounts.resourceStringResource Name.
Gra.Resource.Orphan.Accounts.domainStringDomain Name.
Gra.Resource.Orphan.Accounts.high_riskStringHigh Risk.
Gra.Resource.Orphan.Accounts.is_orphanStringIs Account Orphan.
Gra.Resource.Orphan.Accounts.is_reassignedStringIs account Reassigned.
Gra.Resource.Orphan.Accounts.risk_scoreStringAccount Risk Score.
Gra.Resource.Orphan.Accounts.updated_onDateUpdated On.

Command Example#

!gra-fetch-resource-orphan-accounts resource_name="Windows Security" page=1 max=25

Context Example#

[{
"id":2,
"name":"user1",
"type":null,
"created_on":"02/09/2017 10:00:00",
"department":null,
"description":null,
"resource":"Windows Security",
"domain":"com",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":0,
"updated_on":null
}]

Human Readable Output#

gra-fetch-datasource-highrisk-accounts#


Retrieve high risk accounts for a specified data source.

Base Command#

gra-fetch-datasource-highrisk-accounts

Input#

Argument NameDescriptionRequired
datasource_nameData Source Name.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Datasource.Highrisk.Accounts.idNumberAccount Id.
Gra.Datasource.Highrisk.Accounts.nameStringAccount Name.
Gra.Datasource.Highrisk.Accounts.typeStringAccount type.
Gra.Datasource.Highrisk.Accounts.created_onDateCreated On.
Gra.Datasource.Highrisk.Accounts.departmentStringDepartment.
Gra.Datasource.Highrisk.Accounts.descriptionStringDescription.
Gra.Datasource.Highrisk.Accounts.datasourcenameStringData Source Name.
Gra.Datasource.Highrisk.Accounts.domainStringDomain.
Gra.Datasource.Highrisk.Accounts.high_riskStringHigh Risk.
Gra.Datasource.Highrisk.Accounts.is_orphanStringIs Orphan.
Gra.Datasource.Highrisk.Accounts.is_reassignedStringIs Reassigned.
Gra.Datasource.Highrisk.Accounts.risk_scoreNumberRisk Score.
Gra.Datasource.Highrisk.Accounts.updated_onDateUpdated on.

Command Example#

!gra-fetch-datasource-highrisk-accounts datasource_name="Linux" page=1 max=25

Context Example#

[
{
"id":93,
"name":"Asher.Guthrie",
"type":null,
"created_on":"05/16/2019 06:49:18",
"department":null,
"description":null,
"datasourcename":"Windows Security",
"domain":"in",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":0,
"updated_on":null
}
]

Human Readable Output#

gra-fetch-datasource-hpa#


Retrieve high privileged accounts for a specified data source.

Base Command#

gra-fetch-datasource-hpa

Input#

Argument NameDescriptionRequired
datasource_nameData Source Name.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Datasource.Hpa.idNumberAccount Id.
Gra.Datasource.Hpa.nameStringAccount Name.
Gra.Datasource.Hpa.typeStringAccount type.
Gra.Datasource.Hpa.created_onDateCreated On.
Gra.Datasource.Hpa.departmentStringDepartment.
Gra.Datasource.Hpa.descriptionStringDescription.
Gra.Datasource.Hpa.datasourcenameStringData Source Name.
Gra.Datasource.Hpa.domainStringDomain.
Gra.Datasource.Hpa.high_riskStringHigh Risk.
Gra.Datasource.Hpa.is_orphanStringIs Orphan.
Gra.Datasource.Hpa.is_reassignedStringIs Reassigned.
Gra.Datasource.Hpa.risk_scoreNumberRisk Score.
Gra.Datasource.Hpa.updated_onDateUpdated on.

Command Example#

!gra-fetch-datasource-hpa datasource_name="Linux" page=1 max=25

Context Example#

[
{
"id":93,
"name":"Asher.Guthrie",
"type":null,
"created_on":"05/16/2019 06:49:18",
"department":null,
"description":null,
"datasourcename":"Windows Security",
"domain":"in",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":0,
"updated_on":null
}
]

Human Readable Output#

gra-fetch-datasource-orphan-accounts#


Retrieve orphan / rogue accounts for a specified data source.

Base Command#

gra-fetch-datasource-orphan-accounts

Input#

Argument NameDescriptionRequired
datasource_nameData Source Name.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Datasource.Orphan.Accounts.idNumberAccount Id.
Gra.Datasource.Orphan.Accounts.nameStringAccount Name.
Gra.Datasource.Orphan.Accounts.typeStringAccount type.
Gra.Datasource.Orphan.Accounts.created_onDateCreated On.
Gra.Datasource.Orphan.Accounts.departmentStringDepartment.
Gra.Datasource.Orphan.Accounts.descriptionStringDescription.
Gra.Datasource.Orphan.Accounts.datasourcenameStringData Source Name.
Gra.Datasource.Orphan.Accounts.domainStringDomain.
Gra.Datasource.Orphan.Accounts.high_riskStringHigh Risk.
Gra.Datasource.Orphan.Accounts.is_orphanStringIs Orphan.
Gra.Datasource.Orphan.Accounts.is_reassignedStringIs Reassigned.
Gra.Datasource.Orphan.Accounts.risk_scoreNumberRisk Score.
Gra.Datasource.Orphan.Accounts.updated_onDateUpdated on.

Command Example#

!gra-fetch-datasource-orphan-accounts datasource_name="Linux" page=1 max=25

Context Example#

[
{
"id":93,
"name":"Asher.Guthrie",
"type":null,
"created_on":"05/16/2019 06:49:18",
"department":null,
"description":null,
"datasourcename":"Windows Security",
"domain":"in",
"high_risk":null,
"is_orphan":"No",
"is_reassigned":null,
"risk_score":0,
"updated_on":null
}
]

Human Readable Output#

gra-user-activities#


Retrieve activity for a specified user.

Base Command#

gra-user-activities

Input#

Argument NameDescriptionRequired
employee_idEmployee Id.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.User.Activity.employee_idStringEmployee Id .
Gra.User.Activity.account_nameStringAccount Name .
Gra.User.Activity.datasource_nameStringData Source Name.
Gra.User.Activity.resource_nameStringResource Name. Deprecated. Use Gra.User.Activity.datasource_name instead.
Gra.User.Activity.event_descStringEvent Description .
Gra.User.Activity.event_dateStringEvent Date .
Gra.User.Activity.risk_scoreNumberRisk Score .

Command Example#

!gra-user-activities employee_id="aa17600" page=1 max=25

Context Example#

{
"employee_id":"aa17600",
"account_name":null,
"datasource_name":"Print",
"event_desc":"Print",
"event_date":"09/02/2019 11:51:14",
"risk_score":0.0
}

Human Readable Output#

gra-fetch-users-details#


get details of the user.

Base Command#

gra-fetch-users-details

Input#

Argument NameDescriptionRequired
employee_idEmployee Id.Required

Context Output#

PathTypeDescription
Gra.User.firstNameStringFirst Name.
Gra.User.middleNameStringMiddle Name.
Gra.User.lastNameStringLast Name.
Gra.User.employeeIdStringEmployee Id.
Gra.User.riskScoreStringRisk Score.
Gra.User.userRiskStringUser Risk.
Gra.User.departmentStringDepartment.
Gra.User.emailStringEmail.
Gra.User.phoneStringPhone.
Gra.User.locationStringLocation .
Gra.User.managerStringManager.
Gra.User.titleStringTitle.
Gra.User.joiningDateStringJoining Date.
Gra.User.profilePicturePathStringProfile Picture Path.
Gra.User.exitDateDateExit Date.

Command Example#

!gra-user-activities employee_id="aa17600" page=1 max=25

Context Example#

[
{
"firstName":"Jonathan",
"middleName":null,
"lastName":"Osterman01_NN",
"employeeId":"user1",
"riskScore":88,
"userRisk":88,
"department":"IT",
"email":"Jonathan.Osterman@abc.com",
"phone":"(91)-123-4567-890",
"location":"USA",
"manager":"Thor.Odinson01_NN",
"title":"Sr.Developer",
"joiningDate":"01/01/2017 12:47:00",
"exitDate":"12/31/2019 23:47:00",
"profilePicturePath":null
}
]

Human Readable Output#

gra-highRisk-users#


Retrieve list of all high risk users.

Base Command#

gra-highRisk-users

Input#

Argument NameDescriptionRequired
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Highrisk.Users.firstNameStringFirst Name.
Gra.Highrisk.Users.middleNameStringMiddle Name.
Gra.Highrisk.Users.lastNameStringLast Name.
Gra.Highrisk.Users.employeeIdStringEmployee Id.
Gra.Highrisk.Users.riskScoreNumberRisk Score.
Gra.Highrisk.Users.userRiskNumberUser Risk.
Gra.Highrisk.Users.departmentStringDepartment.
Gra.Highrisk.Users.emailStringEmail.
Gra.Highrisk.Users.phoneStringPhone.
Gra.Highrisk.Users.locationStringLocation.
Gra.Highrisk.Users.managerStringManager.
Gra.Highrisk.Users.titleStringTitle.
Gra.Highrisk.Users.joiningDateDateJoining Date.
Gra.Highrisk.Users.exitDateDateExit Date.
Gra.Highrisk.Users.profilePicturePathStringProfile Picture Path.
Gra.Highrisk.Users.idStringId.
Gra.Highrisk.Users.nameStringName.
Gra.Highrisk.Users.typeStringType.
Gra.Highrisk.Users.descriptionStringDescription.
Gra.Highrisk.Users.domainStringDomain.
Gra.Highrisk.Users.high_riskStringHigh Risk.
Gra.Highrisk.Users.is_orphanStringIs Orphan.
Gra.Highrisk.Users.is_reassignedStringIs Reassigned.
Gra.Highrisk.Users.created_onDateCreated On.
Gra.Highrisk.Users.updated_onDateUpdated On.
Gra.Highrisk.Users.resourceStringResource. Deprecated. Use the Data Source outputs instead.

Command Example#

!gra-highRisk-users page=1 max=25

Context Example#

[
{
"firstName":"Jonathan",
"middleName":null,
"lastName":"Osterman01_NN",
"employeeId":"AB1234",
"riskScore":95,
"userRisk":95,
"department":"IT",
"email":"Jonathan.Osterman@abc.com",
"phone":"(91)-123-4567-890",
"location":"USA",
"manager":"Thor.Odinson01_NN",
"title":"Sr.Developer",
"joiningDate":"01/01/2017 12:47:00",
"exitDate":"12/31/2019 23:47:00",
"profilePicturePath":null
}
]

Human Readable Output#

gra-cases#


Deprecated. GRA Cases are no longer imported by this integration. This command remains available for existing GRACase incidents.

get details of the user.

Base Command#

gra-cases

Input#

Argument NameDescriptionRequired
statusCase Status.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Cases.entityIdNumberEntity Id .
Gra.Cases.entityTypeIdNumberEntity Type Id.
Gra.Cases.entityStringEntity Name.
Gra.Cases.caseIdNumberCase Id .
Gra.Cases.openDateDateCase Open Date.
Gra.Cases.ownerIdNumberOwner Id.
Gra.Cases.ownerTypeStringOwner Type.
Gra.Cases.ownerNameStringOwner Name.
Gra.Cases.riskDateDateRisk Risk.
Gra.Cases.statusStringCase Status .
Gra.Cases.anomaliesStringAnomalies .

Command Example#

!gra-cases status="OPEN" page=1 max=25

Context Example#

[
{
"entityId":366,
"entityTypeId":2,
"entity":"Ulises Ellerby",
"caseId":58,
"openDate":"10/13/2020 18:44:06",
"ownerId":1,
"ownerType":"User",
"ownerName":"Yuki.Jacob",
"riskDate":"10/12/2020 00:00:00",
"status":"Open"
}
]

Human Readable Output#

gra-user-anomalies#


get details of the user.

Base Command#

gra-user-anomalies

Input#

Argument NameDescriptionRequired
employee_idEmployee Id.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.User.Anomalies.anomaly_nameStringAnomaly Name .

Command Example#

!gra-user-anomalies employeeId="AB1234" page=1 max=25

Context Example#

[
{
"anomaly_name":"SOD_role_13oct"
}
]

Human Readable Output#

gra-case-action#


Closing a case and updating the anomaly status as Closed / Risk Managed / Model Reviewed.

Base Command#

gra-case-action

Input#

Argument NameDescriptionRequired
actionActionRequired
caseIdCase IDRequired
subOptionSub OptionRequired
caseCommentCase CommentRequired
riskAcceptDateRisk Accept Date (applicable only in case of closing a case as Risk Managed)Optional

Context Output#

PathTypeDescription
Gra.Case.Action.MessageStringMessage

Command Example#

!gra-case-action action=modelReviewCase caseId=5 subOption="Tuning Required" caseComment="This is Completed"

Context Example#

[
{
"Message": "1 Anomalies in this case closed successfully."
}
]

Human Readable Output#

gra-case-action-anomaly#


Closing an anomaly or anomalies within a case and updating the anomaly status as Closed / Risk Managed / Model Reviewed.

Base Command#

gra-case-action-anomaly

Input#

Argument NameDescriptionRequired
actionActionRequired
caseIdCase IDRequired
anomalyNamesAnomaly NamesRequired
subOptionSub OptionRequired
caseCommentCase CommentRequired
riskAcceptDateRisk Accept Date (applicable only in case of closing a case as Risk Managed)Optional

Context Output#

PathTypeDescription
Gra.Case.Action.Anomaly.MessageStringMessage
Gra.Case.Action.Anomaly.anomalyNameStringAnomaly Name

Command Example#

!gra-case-action-anomaly action=modelReviewCaseAnomaly caseId=5 anomalyNames=anomalyName1 subOption="Tuning Required" caseComment="This is Completed"

Context Example#

[
{
"Message": {
"anomalyName1": "Anomaly risk accepted successfully."
}
}
]

Human Readable Output#

gra-investigate-anomaly-summary#


Retrieve detailed anomaly summary of specified anomaly name.

Base Command#

gra-investigate-anomaly-summary

Input#

Argument NameDescriptionRequired
modelNameModel NameRequired
fromDateFrom Date ( yyyy-MM-dd )Optional
toDateTo Date ( yyyy-MM-dd )Optional

Context Output#

PathTypeDescription
Gra.Investigate.Anomaly.Summary.analyticalFeaturesStringAnalytical Features
Gra.Investigate.Anomaly.Summary.entityCountStringEntity Count
Gra.Investigate.Anomaly.Summary.datasourceCountStringData Source Count
Gra.Investigate.Anomaly.Summary.resourceCountStringResource Count. Deprecated. Use Gra.Investigate.Anomaly.Summary.datasourceCount instead.
Gra.Investigate.Anomaly.Summary.recordsStringRecords
Gra.Investigate.Anomaly.Summary.anomalyBaselineStringAnomaly Baseline
Gra.Investigate.Anomaly.Summary.anomalyLastCatchStringAnomaly Last Catch
Gra.Investigate.Anomaly.Summary.executionDaysStringExecution Days
Gra.Investigate.Anomaly.Summary.chainDetailsStringChain Details
Gra.Investigate.Anomaly.Summary.datasourcenameStringdatasourcename
Gra.Investigate.Anomaly.Summary.resourceNameStringResource Name. Deprecated. Use Gra.Investigate.Anomaly.Summary.datasourcename instead.
Gra.Investigate.Anomaly.Summary.datasourceStringData Source (nested anomalous-account rows)
Gra.Investigate.Anomaly.Summary.typeStringtype
Gra.Investigate.Anomaly.Summary.valueStringvalue
Gra.Investigate.Anomaly.Summary.anomalousActivityNumberanomalousActivity
Gra.Investigate.Anomaly.Summary.anomalyNameStringanomalyName
Gra.Investigate.Anomaly.Summary.classifierStringclassifier
Gra.Investigate.Anomaly.Summary.anomalyFirstCatchStringanomalyFirstCatch
Gra.Investigate.Anomaly.Summary.anomalyDescriptionStringanomalyDescription
Gra.Investigate.Anomaly.Summary.similarTemplateAnomaliesStringSimilar Template Anomalies
Gra.Investigate.Anomaly.Summary.entitiesFlaggedNumberEntities Flagged

Command Example#

!gra-investigate-anomaly-summary modelName=ModelName

Context Example#

{
"analyticalFeatures": {
"eventdesc": 8
},
"entityCount": "466",
"datasourceCount": "4",
"records": {
"anomalyBaseline": "Baseline period is not configured.",
"anomalyLastCatch": "2020-12-06 10:00:59",
"executionDays": "null",
"chainDetails": [
{
"datasourcename": "datasourcename",
"type": "model",
"value": "modelName"
}
],
"anomalousActivity": 0,
"anomalyName": "modelName",
"classifier": "Categories -> Categories Name, Categories -> Default, Data Sources -> datasourcename",
"anomalyFirstCatch": "2020-11-08 12:15:00",
"anomalyDescription": "This template can be used to create models using the saved search query."
},
"similarTemplateAnomalies": {
"anomaly1": 442,
"anomaly2": 4,
"anomaly3": 4,
"anomaly4": 21,
"anomaly5": 8,
"anomaly6": 1
},
"entitiesFlagged": 0
}

Human Readable Output#

gra-analytical-features-entity-value#


Retrieve analytical features for specified entity value and model name.

Base Command#

gra-analytical-features-entity-value

Input#

Argument NameDescriptionRequired
entityValueEntity ValueRequired
modelNameModel NameRequired
fromDateFrom Date ( yyyy-MM-dd )Optional
toDateTo Date ( yyyy-MM-dd )Optional
entityTypeIdEntity Type Id (defaulted to 1)Optional

Context Output#

PathTypeDescription
Gra.Analytical.Features.Entity.Value.analyticalFeaturesStringAnalytical Features
Gra.Analytical.Features.Entity.Value.analyticalFeatureValuesStringAnalytical Feature Values

Command Example#

!gra-analytical-features-entity-value entityValue=EntityValue

Context Example#

{
"analyticalFeatures": {
"analyticalFeature1": 7,
"analyticalFeature2": 1,
"analyticalFeature3": 0
},
"analyticalFeatureValues": {
"analyticalFeature1": {
"analyticalFeature1a": 2,
"analyticalFeature1b": 1,
"analyticalFeature1c": 1
},
"analyticalFeature2": {
"analyticalFeature2a": 6
},
"analyticalFeature3": {
"analyticalFeature3a": 13,
"analyticalFeature3b": 6
}
}
}

Human Readable Output#

gra-cases-anomaly#


Retrieve anomalies for specified case id from GRA and update in Cortex.

Base Command#

gra-cases-anomaly

Input#

Argument NameDescriptionRequired
caseIdGRA Case IdRequired

Context Output#

PathTypeDescription
Gra.Cases.anomalies.anomalyNameStringCases Anomaly name
Gra.Cases.anomalies.riskAcceptedDatedateRisk accepted date of anomaly
Gra.Cases.anomalies.resourceNameStringResource Name
Gra.Cases.anomalies.riskScoreStringRisk score for anomaly
Gra.Cases.anomalies.assigneeStringAssignee name
Gra.Cases.anomalies.assigneeTypeStringAssignee type (User/Role)
Gra.Cases.anomalies.statusStringCurrent status of anomaly

Command Example#

!gra-cases-anomaly caseId=10

Context Example#

[
{
"anomalyName": "Anomaly Name 1",
"riskAcceptedDate": "2023-02-01T18:30:00Z",
"resourceName": "Resource Name 1",
"riskScore": 0,
"assignee": "Assignee 1",
"assigneeType": "User",
"status": "Open"
},
{
"anomalyName": "Anomaly Name 2",
"riskAcceptedDate": null,
"resourceName": "Resource Name 2",
"riskScore": 0,
"assignee": "Assignee 2",
"assigneeType": "User",
"status": "Closed"
}
]

Human Readable Output#

gra-incidents#


Retrieve list of GRA incidents for a specified status.

Base Command#

gra-incidents

Input#

Argument NameDescriptionRequired
statusIncident Status.Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Incidents.entityIdNumberEntity Id.
Gra.Incidents.entityTypeIdNumberEntity Type Id.
Gra.Incidents.entityStringEntity Name.
Gra.Incidents.incidentIdNumberIncident Id.
Gra.Incidents.openDateDateOpen Date.
Gra.Incidents.ownerIdNumberOwner Id.
Gra.Incidents.ownerTypeStringOwner Type.
Gra.Incidents.ownerNameStringOwner Name.
Gra.Incidents.riskDateDateRisk Date.
Gra.Incidents.statusStringStatus.
Gra.Incidents.riskScoreNumberRisk Score.
Gra.Incidents.graweblinkStringGRA Weblink.
Gra.Incidents.anomaliesStringAnomalies.
Gra.Incidents.anomalies.anomalyNameStringIncident Anomaly name.
Gra.Incidents.anomalies.statusStringCurrent status of anomaly.
Gra.Incidents.anomalies.datasourcenameStringData Source Name.
Gra.Incidents.anomalies.assigneeStringAssignee name.
Gra.Incidents.anomalies.assigneeTypeStringAssignee type (User/Role).
Gra.Incidents.anomalies.riskScoreNumberRisk score for anomaly.
Gra.Incidents.anomalies.riskAcceptedDateDateRisk accepted date of anomaly.

Command Example#

!gra-incidents status="OPEN" page=1 max=25

Context Example#

[
{
"entityId":366,
"entityTypeId":2,
"entity":"Ulises Ellerby",
"incidentId":58,
"openDate":"10/13/2020 18:44:06",
"ownerId":1,
"ownerType":"User",
"ownerName":"Yuki.Jacob",
"riskDate":"10/12/2020 00:00:00",
"status":"Open",
"riskScore":72,
"graweblink":"https://gra.example/incidents/58",
"anomalies":[
{
"anomalyName":"Anomaly Name 1",
"status":"Open",
"datasourcename":"Windows Security",
"assignee":"Yuki.Jacob",
"assigneeType":"User",
"riskScore":72,
"riskAcceptedDate":null
}
]
}
]

Human Readable Output#

gra-incident-action#


Close a GRA incident and update anomaly status as Closed / Risk Managed / Model Reviewed.

Base Command#

gra-incident-action

Input#

Argument NameDescriptionRequired
actionAction (closeIncident, modelReviewIncident, riskManageIncident).Required
incidentIdIncident Id.Required
subOptionSub Option.Required
incidentCommentIncident Comment.Required
riskAcceptDateRisk Accept Date in yyyy-MM-dd format (riskManageIncident only).Optional

Context Output#

PathTypeDescription
Gra.Incident.Action.MessageStringMessage.

Command Example#

!gra-incident-action action=closeIncident incidentId=5 subOption="True Incident" incidentComment="Closed from Cortex"

Context Example#

[
{
"Message": "Incident closed successfully."
}
]

Human Readable Output#

gra-incident-action-anomaly#


Close anomalies within a GRA incident.

Base Command#

gra-incident-action-anomaly

Input#

Argument NameDescriptionRequired
actionAction (closeIncidentAnomaly, modelReviewIncidentAnomaly, riskAcceptIncidentAnomaly).Required
incidentIdIncident Id.Required
anomalyNamesAnomaly Names.Required
subOptionSub Option.Required
incidentCommentIncident Comment.Required
riskAcceptDateRisk Accept Date in yyyy-MM-dd format (riskAcceptIncidentAnomaly only).Optional

Context Output#

PathTypeDescription
Gra.Incident.Action.Anomaly.MessageStringMessage.

Command Example#

!gra-incident-action-anomaly action=closeIncidentAnomaly incidentId=5 anomalyNames=anomalyName1 subOption="True Incident" incidentComment="Done"

Context Example#

[
{
"Message": "1 Anomalies in this incident closed successfully."
}
]

Human Readable Output#

gra-incidents-anomaly#


Retrieve anomalies for a specified GRA incident id.

Base Command#

gra-incidents-anomaly

Input#

Argument NameDescriptionRequired
incidentIdGRA Incident Id.Required

Context Output#

PathTypeDescription
Gra.Incidents.anomalies.anomalyNameStringIncident Anomaly name.
Gra.Incidents.anomalies.statusStringCurrent status of anomaly.
Gra.Incidents.anomalies.datasourcenameStringData Source Name.
Gra.Incidents.anomalies.assigneeStringAssignee name.
Gra.Incidents.anomalies.assigneeTypeStringAssignee type (User/Role).
Gra.Incidents.anomalies.riskScoreNumberRisk score for anomaly.
Gra.Incidents.anomalies.riskAcceptedDateDateRisk accepted date of anomaly.

Command Example#

!gra-incidents-anomaly incidentId=10

Context Example#

[
{
"anomalyName": "Anomaly Name 1",
"riskAcceptedDate": "2023-02-01T18:30:00Z",
"datasourcename": "Windows Security",
"riskScore": 0,
"assignee": "Assignee 1",
"assigneeType": "User",
"status": "Open"
},
{
"anomalyName": "Anomaly Name 2",
"riskAcceptedDate": null,
"datasourcename": "Linux",
"riskScore": 0,
"assignee": "Assignee 2",
"assigneeType": "User",
"status": "Closed"
}
]

Human Readable Output#

gra-alerts#


Retrieve list of GRA alerts for a specified status and date range.

Base Command#

gra-alerts

Input#

Argument NameDescriptionRequired
statusStatus (OPEN, CLOSED, IN PROGRESS, ALL).Required
startDateStart Date (yyyy-MM-dd HH:mm:ss).Required
endDateEnd Date (yyyy-MM-dd HH:mm:ss).Required
pagePage no.Optional
maxPer page record countOptional

Context Output#

PathTypeDescription
Gra.Alerts.alertIdNumberAlert Id.
Gra.Alerts.anomalyNameStringAnomaly Name.
Gra.Alerts.entityIdNumberEntity Id.
Gra.Alerts.entityTypeIdNumberEntity Type Id.
Gra.Alerts.entityStringEntity.
Gra.Alerts.statusNameStringStatus.
Gra.Alerts.detectionTimestampDateDetection Timestamp.
Gra.Alerts.severityNumberSeverity.
Gra.Alerts.datasourcenameStringData Source Name.
Gra.Alerts.riskScoreNumberRisk Score.
Gra.Alerts.graweblinkStringGRA Weblink.
Gra.Alerts.incidentTypeStringIncident Type.
Gra.Alerts.assigneeIdsStringAssignee Ids.
Gra.Alerts.assigneeTypeStringAssignee Type.
Gra.Alerts.assigneeStringAssignee.
Gra.Alerts.classifierListStringClassifier List.
Gra.Alerts.subStatusNameStringSub Status Name.

Command Example#

!gra-alerts status="OPEN" startDate="2026-01-01 00:00:00" endDate="2026-12-31 23:59:59" page=1 max=25

Context Example#

[
{
"alertId": 101,
"anomalyName": "Anomaly Name 1",
"entityId": 366,
"entityTypeId": 2,
"entity": "Ulises Ellerby",
"statusName": "OPEN",
"detectionTimestamp": "2026-01-15 10:00:00",
"severity": 3,
"datasourcename": "Windows Security",
"riskScore": 72,
"graweblink": "https://gra.example/alerts/101",
"incidentType": null,
"assigneeIds": "1",
"assigneeType": "GRA_USER",
"assignee": "Yuki.Jacob",
"classifierList": ["Classifier 1"],
"subStatusName": null
}
]

Human Readable Output#

gra-alert-get#


Retrieve a single GRA alert by id.

Base Command#

gra-alert-get

Input#

Argument NameDescriptionRequired
idAlert Id.Required

Context Output#

PathTypeDescription
Gra.Alert.alertIdNumberAlert Id.
Gra.Alert.anomalyNameStringAnomaly Name.
Gra.Alert.entityIdNumberEntity Id.
Gra.Alert.entityTypeIdNumberEntity Type Id.
Gra.Alert.entityStringEntity.
Gra.Alert.statusNameStringStatus.
Gra.Alert.detectionTimestampDateDetection Timestamp.
Gra.Alert.severityNumberSeverity.
Gra.Alert.datasourcenameStringData Source Name.
Gra.Alert.riskScoreNumberRisk Score.
Gra.Alert.graweblinkStringGRA Weblink.
Gra.Alert.incidentTypeStringIncident Type.
Gra.Alert.assigneeIdsStringAssignee Ids.
Gra.Alert.assigneeTypeStringAssignee Type.
Gra.Alert.assigneeStringAssignee.
Gra.Alert.classifierListStringClassifier List.
Gra.Alert.subStatusNameStringSub Status Name.
Gra.Alert.analyticalFeaturesStringAnalytical Features.
Gra.Alert.analyticalFeatureValuesStringAnalytical Feature Values.

Command Example#

!gra-alert-get id=101

Context Example#

{
"alertId": 101,
"anomalyName": "Anomaly Name 1",
"entityId": 366,
"entityTypeId": 2,
"entity": "Ulises Ellerby",
"statusName": "OPEN",
"detectionTimestamp": "2026-01-15 10:00:00",
"severity": 3,
"datasourcename": "Windows Security",
"riskScore": 72,
"graweblink": "https://gra.example/alerts/101",
"incidentType": null,
"assigneeIds": "1",
"assigneeType": "GRA_USER",
"assignee": "Yuki.Jacob",
"classifierList": ["Classifier 1"],
"subStatusName": null,
"analyticalFeatures": {"feature1": "value1"},
"analyticalFeatureValues": {"feature1": ["value1"]}
}

Human Readable Output#

gra-alert-action#


Perform an action on a GRA alert (close, assign, in progress, comment).

Base Command#

gra-alert-action

Input#

Argument NameDescriptionRequired
actionAction (closeAlert, inProgressAlert, assignAlert, addCommentOnAlert).Required
alertIdAlert Id.Required
alertCommentAlert Comment.Required
incidentTypeIncident or Not An Incident (closeAlert).Optional
subStatusClose sub-status (closeAlert).Optional
assigneeTypeAssignee type (assignAlert).Optional
assigneeNameAssignee name (assignAlert).Optional

Context Output#

PathTypeDescription
Gra.Alert.Action.MessageStringMessage.

Command Example#

!gra-alert-action action=closeAlert alertId=101 alertComment="Closed" incidentType="Incident" subStatus="True Positive"

Context Example#

[
{
"Message": "Alert closed successfully."
}
]

Human Readable Output#

gra-alert-comment#


Add a comment on a GRA alert (thin wrapper for addCommentOnAlert).

Base Command#

gra-alert-comment

Input#

Argument NameDescriptionRequired
alertIdAlert Id.Required
alertCommentAlert Comment.Required

Context Output#

PathTypeDescription
Gra.Alert.Action.MessageStringMessage.

Command Example#

!gra-alert-comment alertId=101 alertComment="Investigating"

Context Example#

[
{
"Message": "Comment added successfully."
}
]

Human Readable Output#

gra-alert-assign#


Assign a GRA alert (thin wrapper for assignAlert).

Base Command#

gra-alert-assign

Input#

Argument NameDescriptionRequired
alertIdAlert Id.Required
assigneeTypeAssignee type.Required
assigneeNameAssignee name.Required
alertCommentAlert Comment.Optional

Context Output#

PathTypeDescription
Gra.Alert.Action.MessageStringMessage.

Command Example#

!gra-alert-assign alertId=101 assigneeType=GRA_USER assigneeName="Yuki.Jacob" alertComment="Assigning via XSOAR"

Context Example#

[
{
"Message": "Alert assigned successfully."
}
]

Human Readable Output#

gra-alert-in-progress#


Mark a GRA alert in progress (thin wrapper for inProgressAlert).

Base Command#

gra-alert-in-progress

Input#

Argument NameDescriptionRequired
alertIdAlert Id.Required
alertCommentAlert Comment.Optional

Context Output#

PathTypeDescription
Gra.Alert.Action.MessageStringMessage.

Command Example#

!gra-alert-in-progress alertId=101 alertComment="Working this alert"

Context Example#

[
{
"Message": "Alert set to In Progress."
}
]

Human Readable Output#

gra-alert-update-history#


Retrieve update history for a GRA alert.

Base Command#

gra-alert-update-history

Input#

Argument NameDescriptionRequired
alertIdAlert Id.Required

Context Output#

PathTypeDescription
Gra.Alert.History.countNumberNumber of history entries.
Gra.Alert.History.alertDetailsStringAlert history details.
Gra.Alert.History.alertDetails.firstNameStringFirst name.
Gra.Alert.History.alertDetails.lastNameStringLast name.
Gra.Alert.History.alertDetails.addedDateDateAdded date.
Gra.Alert.History.alertDetails.eventByStringEvent by.
Gra.Alert.History.alertDetails.addedByStringAdded by.
Gra.Alert.History.alertDetails.idNumberHistory entry id.
Gra.Alert.History.alertDetails.profilePicturePathStringProfile picture path.
Gra.Alert.History.alertDetails.actionNameStringAction name.
Gra.Alert.History.alertDetails.commentStringComment.

Command Example#

!gra-alert-update-history alertId=101

Context Example#

{
"count": 1,
"alertDetails": [
{
"firstName": "Yuki",
"lastName": "Jacob",
"addedDate": "2026-01-15 10:05:00",
"eventBy": "Yuki.Jacob",
"addedBy": "Yuki.Jacob",
"id": 1,
"profilePicturePath": null,
"actionName": "Comment",
"comment": "Investigating"
}
]
}

Human Readable Output#

gra-validate-api#


Verifies the Gurucul platform's operational status by assessing system health, reviewing logs, and checking key performance indicators for any errors.

Base Command#

gra-validate-api

Command Example#

!gra-validate-api

Context Example#

ok

Human Readable Output#