Gurucul-GRA
This Integration is part of the Gurucul Risk Analytics Pack.#
Supported versions
Available on Cortex XSOAR and Cortex XSIAM.
Gurucul Risk Analytics (GRA) is a data science backed cloud native platform that predicts, detects and prevents breaches. It ingests and analyzes massive amounts of data from the network, IT systems, cloud platforms, EDR, applications, IoT, HR and much more to give you a comprehensive contextual view of user and entity behaviors. This integration fetches GRA Incidents or Alerts into Cortex and exposes War Room commands for investigation and actions. Workflows can be configured in Cortex based on the commands provided by GRA.
Please make sure you look at the integration source code and comments.
Configure Gurucul in Cortex#
| Parameter | Description | Required |
|---|---|---|
| Server URL (e.g. https://example.net) | The GRA server URL. | True |
| Authorization Key | The API key used to authenticate to GRA. | True |
| Fetch incidents | Whether this instance fetches incidents. | False |
| Incident type | The incident type to assign to fetched incidents. | False |
| Trust any certificate (not secure) | Whether to trust any certificate. | False |
| Use system proxy settings | Whether to use the system proxy settings. | False |
| First fetch time | The first-fetch time window used only when no ID cursor exists yet. | False |
| Maximum number of incidents per fetch | The maximum number of incidents to fetch per run. | False |
| Fetch type | The objects to import from GRA (Incidents or Alerts). Default: Incidents. Cases are no longer fetched. Use a separate instance for Alerts. | False |
| GRA server timezone | Set the timezone of the GRA server (IANA id). Used when fetching Incidents and Alerts. Not used for First fetch time. Default UTC. | False |
Fetch setup (Incidents vs Alerts)#
Use two integration instances when you need both types:
| Instance | Fetch type | Classifier | Mapper (incoming) | Incident type |
|---|---|---|---|---|
| Incidents | Incidents (YAML default) | None / Select | GRAIncident-Mapper (YAML default) | GRAIncident (YAML default) |
| Alerts | Alerts | None / Select | GRAAlert-Mapper | GRAAlert |
Important: Check Do not use by default on all Gurucul-GRA instances. If it is unchecked, Cortex can run War Room commands against this instance alongside all other enabled instances that are still use-by-default.
New instances default to Fetch type = Incidents, with Mapper (incoming) = GRAIncident-Mapper and Incident type = GRAIncident (YAML defaults). On an Alerts instance, set Fetch type to Alerts, then set Mapper and Incident type to the Alert values above so fields and layouts map correctly.
Set GRA server timezone to the GRA server timezone so Occurred matches GRA (default UTC). It is not used for First fetch time. War Room commands still return GRA date strings unchanged.
Upgrading from Case fetch (2.1.0)#
If you already run a Gurucul instance that fetched Cases, update carefully so fetch does not run with the wrong type/mapper mid-upgrade:
- Disable Fetches incidents on the existing Cases instance (or disable the instance).
- Update the Gurucul pack to 2.1.0 .
- Open the same instance and confirm or set:
- Classifier = None / Select
- Fetch type =
Incidents(integration default; was not used for Cases fetch on older versions) - Mapper (incoming) =
GRAIncident-Mapper(default on new instances) - Incident type =
GRAIncident(default on new instances)
- Check Do not use by default checkbox.
- Save, then re-enable fetch.
Notes:
- Existing GRACase incidents in Cortex remain; use
gra-case-*commands for actions on them. Cases are no longer fetched. - If the instance last-run still has
maxCaseIdand nomaxIncidentId, that Case cursor is reused asmaxIncidentIdso the first Incident fetch does not use the initial date window from First fetch time. - For Alerts, create a separate instance using the Alerts row in the table above.
- GRA nomenclature: GRA now uses Data Source instead of Resource. Incident and Alert fields use Data Source. Deprecated Resource account commands remain; prefer the Data Source replacements. Existing GRACase incidents and Case commands keep Resource so they continue to work. The Alert field GRA Alert Resource is replaced by GRA Alert Data Source.
Commands#
You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
Important: Always specify the target instance on War Room commands by passing
using="InstanceName", for example!gra-incidents status=OPEN using="Your-Incidents-instance". Withoutusing, the command may not reach the intended Gurucul-GRA instance and can fail or return results from another instance.
gra-fetch-users#
Retrieve List of All Users (Identities)
Base Command#
gra-fetch-users
Input#
| Argument Name | Description | Required |
|---|---|---|
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Users.firstName | String | First Name. |
| Gra.Users.middleName | String | Middle Name. |
| Gra.Users.lastName | String | Last Name. |
| Gra.Users.employeeId | String | Employee Name. |
| Gra.Users.riskScore | String | Risk Name. |
| Gra.Users.department | String | Department. |
| Gra.Users.email | String | Users email. |
| Gra.Users.phone | String | Users Phone no. |
| Gra.Users.location | String | Location. |
| Gra.Users.manager | String | Users Manager. |
| Gra.Users.title | String | Users title. |
| Gra.Users.joiningDate | String | Joining Date. |
| Gra.Users.exitDate | String | Exit Date. |
| Gra.Users.userRisk | String | User Risk. |
| Gra.Users.profilePicturePath | String | Profile Picture Path. |
Command Example#
!gra-fetch-users page=1 max=25
Context Example#
Base Command#
gra-fetch-accounts
Retrieve all Accounts Information
Input#
| Argument Name | Description | Required |
|---|---|---|
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Accounts.id | Number | Account Id. |
| Gra.Accounts.name | String | Account Name. |
| Gra.Accounts.type | String | Account type. |
| Gra.Accounts.created_on | Date | Created On. |
| Gra.Accounts.department | String | Department. |
| Gra.Accounts.description | String | Description. |
| Gra.Accounts.datasourcename | String | Data Source Name. |
| Gra.Accounts.resource | String | Resource. Deprecated. Use Gra.Accounts.datasourcename instead. |
| Gra.Accounts.domain | String | Domain. |
| Gra.Accounts.high_risk | String | High Risk. |
| Gra.Accounts.is_orphan | String | Is Orphan. |
| Gra.Accounts.is_reassigned | String | Is Reassigned. |
| Gra.Accounts.risk_score | Number | Risk Score. |
| Gra.Accounts.updated_on | Date | Updated on. |
Command Example#
!gra-fetch-accounts page=1 max=25
Context Example#
Human Readable Output#
Results#
gra-fetch-active-resource-accounts#
Retrieve List of All Active Accounts for a Given Resource.
Deprecated. Use gra-fetch-active-datasource-accounts instead.
Base Command#
!gra-fetch-active-resource-accounts
Input#
| Argument Name | Description | Required |
|---|---|---|
| resource_name | Resource Name. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Active.Resource.Accounts.id | Number | Account Id. |
| Gra.Active.Resource.Accounts.name | String | Account Name. |
| Gra.Active.Resource.Accounts.type | String | Account type. |
| Gra.Active.Resource.Accounts.created_on | Date | Created On. |
| Gra.Active.Resource.Accounts.department | String | Department. |
| Gra.Active.Resource.Accounts.description | String | Description. |
| Gra.Active.Resource.Accounts.resource | String | Resource Name. |
| Gra.Active.Resource.Accounts.domain | String | Domain. |
| Gra.Active.Resource.Accounts.high_risk | String | High Risk. |
| Gra.Active.Resource.Accounts.is_orphan | String | Is Orphan. |
| Gra.Active.Resource.Accounts.is_reassigned | String | Is Reassigned. |
| Gra.Active.Resource.Accounts.risk_score | Number | Risk Score. |
| Gra.Active.Resource.Accounts.updated_on | Date | Updated on. |
Command Example#
!gra-fetch-active-resource-accounts resource_name="Linux" page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-active-datasource-accounts#
Retrieve list of all active accounts for a specified data source.
Base Command#
gra-fetch-active-datasource-accounts
Input#
| Argument Name | Description | Required |
|---|---|---|
| datasource_name | Data Source Name. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Active.Datasource.Accounts.id | Number | Account Id. |
| Gra.Active.Datasource.Accounts.name | String | Account Name. |
| Gra.Active.Datasource.Accounts.type | String | Account type. |
| Gra.Active.Datasource.Accounts.created_on | Date | Created On. |
| Gra.Active.Datasource.Accounts.department | String | Department. |
| Gra.Active.Datasource.Accounts.description | String | Description. |
| Gra.Active.Datasource.Accounts.datasourcename | String | Data Source Name. |
| Gra.Active.Datasource.Accounts.domain | String | Domain. |
| Gra.Active.Datasource.Accounts.high_risk | String | High Risk. |
| Gra.Active.Datasource.Accounts.is_orphan | String | Is Orphan. |
| Gra.Active.Datasource.Accounts.is_reassigned | String | Is Reassigned. |
| Gra.Active.Datasource.Accounts.risk_score | Number | Risk Score. |
| Gra.Active.Datasource.Accounts.updated_on | Date | Updated on. |
Command Example#
!gra-fetch-active-datasource-accounts datasource_name="Linux" page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-user-accounts#
Retrieve List of All Active Accounts and Details for a Given User.
Base Command#
gra-fetch-user-accounts
Input#
| Argument Name | Description | Required |
|---|---|---|
| employee_id | Employee ID. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.User.Accounts.id | Number | User Account Relation Id . |
| Gra.User.Accounts.name | String | Account Name. |
| Gra.User.Accounts.type | String | Account Type. |
| Gra.User.Accounts.created_on | Date | Created On. |
| Gra.User.Accounts.department | String | Department. |
| Gra.User.Accounts.description | String | Description. |
| Gra.User.Accounts.datasourcename | String | Data Source Name. |
| Gra.User.Accounts.resource | String | Resource. Deprecated. Use Gra.User.Accounts.datasourcename instead. |
| Gra.User.Accounts.domain | String | Domain Name. |
| Gra.User.Accounts.high_risk | String | High Risk. |
| Gra.User.Accounts.is_orphan | String | Is Account Orphan. |
| Gra.User.Accounts.is_reassigned | String | Is account Reassigned. |
| Gra.User.Accounts.risk_score | String | Account Risk Score. |
| Gra.User.Accounts.updated_on | Date | Updated On. |
Command Example#
!gra-fetch-user-accounts employee_id="Alec.Holland01_NN" page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-resource-highrisk-accounts#
Retrieve High Risk Accounts for a Given Resource
Deprecated. Use gra-fetch-datasource-highrisk-accounts instead.
Base Command#
gra-fetch-resource-highrisk-accounts
Input#
| Argument Name | Description | Required |
|---|---|---|
| resource_name | Resource Name. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Resource.Highrisk.Accounts.id | Number | User Account Relation Id . |
| Gra.Resource.Highrisk.Accounts.name | String | Account Name. |
| Gra.Resource.Highrisk.Accounts.type | String | Account Type. |
| Gra.Resource.Highrisk.Accounts.created_on | Date | Created On. |
| Gra.Resource.Highrisk.Accounts.department | String | Department. |
| Gra.Resource.Highrisk.Accounts.description | String | Description. |
| Gra.Resource.Highrisk.Accounts.resource | String | Resource Name. |
| Gra.Resource.Highrisk.Accounts.domain | String | Domain Name. |
| Gra.Resource.Highrisk.Accounts.high_risk | String | High Risk. |
| Gra.Resource.Highrisk.Accounts.is_orphan | String | Is Account Orphan. |
| Gra.Resource.Highrisk.Accounts.is_reassigned | String | Is account Reassigned. |
| Gra.Resource.Highrisk.Accounts.risk_score | String | Account Risk Score. |
| Gra.Resource.Highrisk.Accounts.updated_on | Date | Updated On. |
Command Example#
!gra-fetch-resource-highrisk-accounts resource_name="Windows Security" page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-hpa#
Retrieve List of All High Risk Privileged Accounts.
Base Command#
!gra-fetch-hpa
Input#
| Argument Name | Description | Required |
|---|---|---|
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Hpa.id | Number | User Account Relation Id . |
| Gra.Hpa.name | String | Account Name. |
| Gra.Hpa.type | String | Account Type. |
| Gra.Hpa.created_on | Date | Created On. |
| Gra.Hpa.department | String | Department. |
| Gra.Hpa.description | String | Description. |
| Gra.Hpa.datasourcename | String | Data Source Name. |
| Gra.Hpa.resource | String | Resource. Deprecated. Use Gra.Hpa.datasourcename instead. |
| Gra.Hpa.domain | String | Domain Name. |
| Gra.Hpa.high_risk | String | High Risk. |
| Gra.Hpa.is_orphan | String | Is Account Orphan. |
| Gra.Hpa.is_reassigned | String | Is account Reassigned. |
| Gra.Hpa.risk_score | String | Account Risk Score. |
| Gra.Hpa.updated_on | Date | Updated On. |
Command Example#
!gra-fetch-hpa page=1 max=25
Context Example#
Human Readable Output#
#
gra-fetch-resource-hpa#
Retrieve all High Privileged Accounts for a Given Resource.
Deprecated. Use gra-fetch-datasource-hpa instead.
Base Command#
gra-fetch-resource-hpa
Input#
| Argument Name | Description | Required |
|---|---|---|
| resource_name | Resource Name. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Resource.Hpa.id | Number | User Account Relation Id . |
| Gra.Resource.Hpa.name | String | Account Name. |
| Gra.Resource.Hpa.type | String | Account Type. |
| Gra.Resource.Hpa.created_on | Date | Created On. |
| Gra.Resource.Hpa.department | String | Department. |
| Gra.Resource.Hpa.description | String | Description. |
| Gra.Resource.Hpa.resource | String | Resource Name. |
| Gra.Resource.Hpa.domain | String | Domain Name. |
| Gra.Resource.Hpa.high_risk | String | High Risk. |
| Gra.Resource.Hpa.is_orphan | String | Is Account Orphan. |
| Gra.Resource.Hpa.is_reassigned | String | Is account Reassigned. |
| Gra.Resource.Hpa.risk_score | String | Account Risk Score. |
| Gra.Resource.Hpa.updated_on | Date | Updated On. |
Command Example#
!gra-fetch-resource-hpa resource_name="Linux" page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-orphan-accounts#
Retrieve List of All Orphan / Rogue Accounts.
Base Command#
gra-fetch-orphan-accounts
Input#
| Argument Name | Description | Required |
|---|---|---|
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Orphan.Accounts.id | Number | User Account Relation Id . |
| Gra.Orphan.Accounts.name | String | Account Name. |
| Gra.Orphan.Accounts.type | String | Account Type. |
| Gra.Orphan.Accounts.created_on | Date | Created On. |
| Gra.Orphan.Accounts.department | String | Department. |
| Gra.Orphan.Accounts.description | String | Description. |
| Gra.Orphan.Accounts.datasourcename | String | Data Source Name. |
| Gra.Orphan.Accounts.resource | String | Resource. Deprecated. Use Gra.Orphan.Accounts.datasourcename instead. |
| Gra.Orphan.Accounts.domain | String | Domain Name. |
| Gra.Orphan.Accounts.high_risk | String | High Risk. |
| Gra.Orphan.Accounts.is_orphan | String | Is Account Orphan. |
| Gra.Orphan.Accounts.is_reassigned | String | Is account Reassigned. |
| Gra.Orphan.Accounts.risk_score | String | Account Risk Score. |
| Gra.Orphan.Accounts.updated_on | Date | Updated On. |
Command Example#
!gra-fetch-orphan-accounts page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-resource-orphan-accounts#
Retrieve All Orphan / Rogue Accounts for a Given Resource.
Deprecated. Use gra-fetch-datasource-orphan-accounts instead.
Base Command#
gra-fetch-resource-orphan-accounts
Input#
| Argument Name | Description | Required |
|---|---|---|
| resource_name | Resource Name. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Resource.Orphan.Accounts.id | Number | User Account Relation Id . |
| Gra.Resource.Orphan.Accounts.name | String | Account Name. |
| Gra.Resource.Orphan.Accounts.type | String | Account Type. |
| Gra.Resource.Orphan.Accounts.created_on | Date | Created On. |
| Gra.Resource.Orphan.Accounts.department | String | Department. |
| Gra.Resource.Orphan.Accounts.description | String | Description. |
| Gra.Resource.Orphan.Accounts.resource | String | Resource Name. |
| Gra.Resource.Orphan.Accounts.domain | String | Domain Name. |
| Gra.Resource.Orphan.Accounts.high_risk | String | High Risk. |
| Gra.Resource.Orphan.Accounts.is_orphan | String | Is Account Orphan. |
| Gra.Resource.Orphan.Accounts.is_reassigned | String | Is account Reassigned. |
| Gra.Resource.Orphan.Accounts.risk_score | String | Account Risk Score. |
| Gra.Resource.Orphan.Accounts.updated_on | Date | Updated On. |
Command Example#
!gra-fetch-resource-orphan-accounts resource_name="Windows Security" page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-datasource-highrisk-accounts#
Retrieve high risk accounts for a specified data source.
Base Command#
gra-fetch-datasource-highrisk-accounts
Input#
| Argument Name | Description | Required |
|---|---|---|
| datasource_name | Data Source Name. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Datasource.Highrisk.Accounts.id | Number | Account Id. |
| Gra.Datasource.Highrisk.Accounts.name | String | Account Name. |
| Gra.Datasource.Highrisk.Accounts.type | String | Account type. |
| Gra.Datasource.Highrisk.Accounts.created_on | Date | Created On. |
| Gra.Datasource.Highrisk.Accounts.department | String | Department. |
| Gra.Datasource.Highrisk.Accounts.description | String | Description. |
| Gra.Datasource.Highrisk.Accounts.datasourcename | String | Data Source Name. |
| Gra.Datasource.Highrisk.Accounts.domain | String | Domain. |
| Gra.Datasource.Highrisk.Accounts.high_risk | String | High Risk. |
| Gra.Datasource.Highrisk.Accounts.is_orphan | String | Is Orphan. |
| Gra.Datasource.Highrisk.Accounts.is_reassigned | String | Is Reassigned. |
| Gra.Datasource.Highrisk.Accounts.risk_score | Number | Risk Score. |
| Gra.Datasource.Highrisk.Accounts.updated_on | Date | Updated on. |
Command Example#
!gra-fetch-datasource-highrisk-accounts datasource_name="Linux" page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-datasource-hpa#
Retrieve high privileged accounts for a specified data source.
Base Command#
gra-fetch-datasource-hpa
Input#
| Argument Name | Description | Required |
|---|---|---|
| datasource_name | Data Source Name. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Datasource.Hpa.id | Number | Account Id. |
| Gra.Datasource.Hpa.name | String | Account Name. |
| Gra.Datasource.Hpa.type | String | Account type. |
| Gra.Datasource.Hpa.created_on | Date | Created On. |
| Gra.Datasource.Hpa.department | String | Department. |
| Gra.Datasource.Hpa.description | String | Description. |
| Gra.Datasource.Hpa.datasourcename | String | Data Source Name. |
| Gra.Datasource.Hpa.domain | String | Domain. |
| Gra.Datasource.Hpa.high_risk | String | High Risk. |
| Gra.Datasource.Hpa.is_orphan | String | Is Orphan. |
| Gra.Datasource.Hpa.is_reassigned | String | Is Reassigned. |
| Gra.Datasource.Hpa.risk_score | Number | Risk Score. |
| Gra.Datasource.Hpa.updated_on | Date | Updated on. |
Command Example#
!gra-fetch-datasource-hpa datasource_name="Linux" page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-datasource-orphan-accounts#
Retrieve orphan / rogue accounts for a specified data source.
Base Command#
gra-fetch-datasource-orphan-accounts
Input#
| Argument Name | Description | Required |
|---|---|---|
| datasource_name | Data Source Name. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Datasource.Orphan.Accounts.id | Number | Account Id. |
| Gra.Datasource.Orphan.Accounts.name | String | Account Name. |
| Gra.Datasource.Orphan.Accounts.type | String | Account type. |
| Gra.Datasource.Orphan.Accounts.created_on | Date | Created On. |
| Gra.Datasource.Orphan.Accounts.department | String | Department. |
| Gra.Datasource.Orphan.Accounts.description | String | Description. |
| Gra.Datasource.Orphan.Accounts.datasourcename | String | Data Source Name. |
| Gra.Datasource.Orphan.Accounts.domain | String | Domain. |
| Gra.Datasource.Orphan.Accounts.high_risk | String | High Risk. |
| Gra.Datasource.Orphan.Accounts.is_orphan | String | Is Orphan. |
| Gra.Datasource.Orphan.Accounts.is_reassigned | String | Is Reassigned. |
| Gra.Datasource.Orphan.Accounts.risk_score | Number | Risk Score. |
| Gra.Datasource.Orphan.Accounts.updated_on | Date | Updated on. |
Command Example#
!gra-fetch-datasource-orphan-accounts datasource_name="Linux" page=1 max=25
Context Example#
Human Readable Output#
gra-user-activities#
Retrieve activity for a specified user.
Base Command#
gra-user-activities
Input#
| Argument Name | Description | Required |
|---|---|---|
| employee_id | Employee Id. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.User.Activity.employee_id | String | Employee Id . |
| Gra.User.Activity.account_name | String | Account Name . |
| Gra.User.Activity.datasource_name | String | Data Source Name. |
| Gra.User.Activity.resource_name | String | Resource Name. Deprecated. Use Gra.User.Activity.datasource_name instead. |
| Gra.User.Activity.event_desc | String | Event Description . |
| Gra.User.Activity.event_date | String | Event Date . |
| Gra.User.Activity.risk_score | Number | Risk Score . |
Command Example#
!gra-user-activities employee_id="aa17600" page=1 max=25
Context Example#
Human Readable Output#
gra-fetch-users-details#
get details of the user.
Base Command#
gra-fetch-users-details
Input#
| Argument Name | Description | Required |
|---|---|---|
| employee_id | Employee Id. | Required |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.User.firstName | String | First Name. |
| Gra.User.middleName | String | Middle Name. |
| Gra.User.lastName | String | Last Name. |
| Gra.User.employeeId | String | Employee Id. |
| Gra.User.riskScore | String | Risk Score. |
| Gra.User.userRisk | String | User Risk. |
| Gra.User.department | String | Department. |
| Gra.User.email | String | Email. |
| Gra.User.phone | String | Phone. |
| Gra.User.location | String | Location . |
| Gra.User.manager | String | Manager. |
| Gra.User.title | String | Title. |
| Gra.User.joiningDate | String | Joining Date. |
| Gra.User.profilePicturePath | String | Profile Picture Path. |
| Gra.User.exitDate | Date | Exit Date. |
Command Example#
!gra-user-activities employee_id="aa17600" page=1 max=25
Context Example#
Human Readable Output#
gra-highRisk-users#
Retrieve list of all high risk users.
Base Command#
gra-highRisk-users
Input#
| Argument Name | Description | Required |
|---|---|---|
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Highrisk.Users.firstName | String | First Name. |
| Gra.Highrisk.Users.middleName | String | Middle Name. |
| Gra.Highrisk.Users.lastName | String | Last Name. |
| Gra.Highrisk.Users.employeeId | String | Employee Id. |
| Gra.Highrisk.Users.riskScore | Number | Risk Score. |
| Gra.Highrisk.Users.userRisk | Number | User Risk. |
| Gra.Highrisk.Users.department | String | Department. |
| Gra.Highrisk.Users.email | String | Email. |
| Gra.Highrisk.Users.phone | String | Phone. |
| Gra.Highrisk.Users.location | String | Location. |
| Gra.Highrisk.Users.manager | String | Manager. |
| Gra.Highrisk.Users.title | String | Title. |
| Gra.Highrisk.Users.joiningDate | Date | Joining Date. |
| Gra.Highrisk.Users.exitDate | Date | Exit Date. |
| Gra.Highrisk.Users.profilePicturePath | String | Profile Picture Path. |
| Gra.Highrisk.Users.id | String | Id. |
| Gra.Highrisk.Users.name | String | Name. |
| Gra.Highrisk.Users.type | String | Type. |
| Gra.Highrisk.Users.description | String | Description. |
| Gra.Highrisk.Users.domain | String | Domain. |
| Gra.Highrisk.Users.high_risk | String | High Risk. |
| Gra.Highrisk.Users.is_orphan | String | Is Orphan. |
| Gra.Highrisk.Users.is_reassigned | String | Is Reassigned. |
| Gra.Highrisk.Users.created_on | Date | Created On. |
| Gra.Highrisk.Users.updated_on | Date | Updated On. |
| Gra.Highrisk.Users.resource | String | Resource. Deprecated. Use the Data Source outputs instead. |
Command Example#
!gra-highRisk-users page=1 max=25
Context Example#
Human Readable Output#
gra-cases#
Deprecated. GRA Cases are no longer imported by this integration. This command remains available for existing GRACase incidents.
get details of the user.
Base Command#
gra-cases
Input#
| Argument Name | Description | Required |
|---|---|---|
| status | Case Status. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Cases.entityId | Number | Entity Id . |
| Gra.Cases.entityTypeId | Number | Entity Type Id. |
| Gra.Cases.entity | String | Entity Name. |
| Gra.Cases.caseId | Number | Case Id . |
| Gra.Cases.openDate | Date | Case Open Date. |
| Gra.Cases.ownerId | Number | Owner Id. |
| Gra.Cases.ownerType | String | Owner Type. |
| Gra.Cases.ownerName | String | Owner Name. |
| Gra.Cases.riskDate | Date | Risk Risk. |
| Gra.Cases.status | String | Case Status . |
| Gra.Cases.anomalies | String | Anomalies . |
Command Example#
!gra-cases status="OPEN" page=1 max=25
Context Example#
Human Readable Output#
gra-user-anomalies#
get details of the user.
Base Command#
gra-user-anomalies
Input#
| Argument Name | Description | Required |
|---|---|---|
| employee_id | Employee Id. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.User.Anomalies.anomaly_name | String | Anomaly Name . |
Command Example#
!gra-user-anomalies employeeId="AB1234" page=1 max=25
Context Example#
Human Readable Output#
gra-case-action#
Closing a case and updating the anomaly status as Closed / Risk Managed / Model Reviewed.
Base Command#
gra-case-action
Input#
| Argument Name | Description | Required |
|---|---|---|
| action | Action | Required |
| caseId | Case ID | Required |
| subOption | Sub Option | Required |
| caseComment | Case Comment | Required |
| riskAcceptDate | Risk Accept Date (applicable only in case of closing a case as Risk Managed) | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Case.Action.Message | String | Message |
Command Example#
!gra-case-action action=modelReviewCase caseId=5 subOption="Tuning Required" caseComment="This is Completed"
Context Example#
Human Readable Output#
gra-case-action-anomaly#
Closing an anomaly or anomalies within a case and updating the anomaly status as Closed / Risk Managed / Model Reviewed.
Base Command#
gra-case-action-anomaly
Input#
| Argument Name | Description | Required |
|---|---|---|
| action | Action | Required |
| caseId | Case ID | Required |
| anomalyNames | Anomaly Names | Required |
| subOption | Sub Option | Required |
| caseComment | Case Comment | Required |
| riskAcceptDate | Risk Accept Date (applicable only in case of closing a case as Risk Managed) | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Case.Action.Anomaly.Message | String | Message |
| Gra.Case.Action.Anomaly.anomalyName | String | Anomaly Name |
Command Example#
!gra-case-action-anomaly action=modelReviewCaseAnomaly caseId=5 anomalyNames=anomalyName1 subOption="Tuning Required" caseComment="This is Completed"
Context Example#
Human Readable Output#
gra-investigate-anomaly-summary#
Retrieve detailed anomaly summary of specified anomaly name.
Base Command#
gra-investigate-anomaly-summary
Input#
| Argument Name | Description | Required |
|---|---|---|
| modelName | Model Name | Required |
| fromDate | From Date ( yyyy-MM-dd ) | Optional |
| toDate | To Date ( yyyy-MM-dd ) | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Investigate.Anomaly.Summary.analyticalFeatures | String | Analytical Features |
| Gra.Investigate.Anomaly.Summary.entityCount | String | Entity Count |
| Gra.Investigate.Anomaly.Summary.datasourceCount | String | Data Source Count |
| Gra.Investigate.Anomaly.Summary.resourceCount | String | Resource Count. Deprecated. Use Gra.Investigate.Anomaly.Summary.datasourceCount instead. |
| Gra.Investigate.Anomaly.Summary.records | String | Records |
| Gra.Investigate.Anomaly.Summary.anomalyBaseline | String | Anomaly Baseline |
| Gra.Investigate.Anomaly.Summary.anomalyLastCatch | String | Anomaly Last Catch |
| Gra.Investigate.Anomaly.Summary.executionDays | String | Execution Days |
| Gra.Investigate.Anomaly.Summary.chainDetails | String | Chain Details |
| Gra.Investigate.Anomaly.Summary.datasourcename | String | datasourcename |
| Gra.Investigate.Anomaly.Summary.resourceName | String | Resource Name. Deprecated. Use Gra.Investigate.Anomaly.Summary.datasourcename instead. |
| Gra.Investigate.Anomaly.Summary.datasource | String | Data Source (nested anomalous-account rows) |
| Gra.Investigate.Anomaly.Summary.type | String | type |
| Gra.Investigate.Anomaly.Summary.value | String | value |
| Gra.Investigate.Anomaly.Summary.anomalousActivity | Number | anomalousActivity |
| Gra.Investigate.Anomaly.Summary.anomalyName | String | anomalyName |
| Gra.Investigate.Anomaly.Summary.classifier | String | classifier |
| Gra.Investigate.Anomaly.Summary.anomalyFirstCatch | String | anomalyFirstCatch |
| Gra.Investigate.Anomaly.Summary.anomalyDescription | String | anomalyDescription |
| Gra.Investigate.Anomaly.Summary.similarTemplateAnomalies | String | Similar Template Anomalies |
| Gra.Investigate.Anomaly.Summary.entitiesFlagged | Number | Entities Flagged |
Command Example#
!gra-investigate-anomaly-summary modelName=ModelName
Context Example#
Human Readable Output#
gra-analytical-features-entity-value#
Retrieve analytical features for specified entity value and model name.
Base Command#
gra-analytical-features-entity-value
Input#
| Argument Name | Description | Required |
|---|---|---|
| entityValue | Entity Value | Required |
| modelName | Model Name | Required |
| fromDate | From Date ( yyyy-MM-dd ) | Optional |
| toDate | To Date ( yyyy-MM-dd ) | Optional |
| entityTypeId | Entity Type Id (defaulted to 1) | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Analytical.Features.Entity.Value.analyticalFeatures | String | Analytical Features |
| Gra.Analytical.Features.Entity.Value.analyticalFeatureValues | String | Analytical Feature Values |
Command Example#
!gra-analytical-features-entity-value entityValue=EntityValue
Context Example#
Human Readable Output#
gra-cases-anomaly#
Retrieve anomalies for specified case id from GRA and update in Cortex.
Base Command#
gra-cases-anomaly
Input#
| Argument Name | Description | Required |
|---|---|---|
| caseId | GRA Case Id | Required |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Cases.anomalies.anomalyName | String | Cases Anomaly name |
| Gra.Cases.anomalies.riskAcceptedDate | date | Risk accepted date of anomaly |
| Gra.Cases.anomalies.resourceName | String | Resource Name |
| Gra.Cases.anomalies.riskScore | String | Risk score for anomaly |
| Gra.Cases.anomalies.assignee | String | Assignee name |
| Gra.Cases.anomalies.assigneeType | String | Assignee type (User/Role) |
| Gra.Cases.anomalies.status | String | Current status of anomaly |
Command Example#
!gra-cases-anomaly caseId=10
Context Example#
Human Readable Output#
gra-incidents#
Retrieve list of GRA incidents for a specified status.
Base Command#
gra-incidents
Input#
| Argument Name | Description | Required |
|---|---|---|
| status | Incident Status. | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Incidents.entityId | Number | Entity Id. |
| Gra.Incidents.entityTypeId | Number | Entity Type Id. |
| Gra.Incidents.entity | String | Entity Name. |
| Gra.Incidents.incidentId | Number | Incident Id. |
| Gra.Incidents.openDate | Date | Open Date. |
| Gra.Incidents.ownerId | Number | Owner Id. |
| Gra.Incidents.ownerType | String | Owner Type. |
| Gra.Incidents.ownerName | String | Owner Name. |
| Gra.Incidents.riskDate | Date | Risk Date. |
| Gra.Incidents.status | String | Status. |
| Gra.Incidents.riskScore | Number | Risk Score. |
| Gra.Incidents.graweblink | String | GRA Weblink. |
| Gra.Incidents.anomalies | String | Anomalies. |
| Gra.Incidents.anomalies.anomalyName | String | Incident Anomaly name. |
| Gra.Incidents.anomalies.status | String | Current status of anomaly. |
| Gra.Incidents.anomalies.datasourcename | String | Data Source Name. |
| Gra.Incidents.anomalies.assignee | String | Assignee name. |
| Gra.Incidents.anomalies.assigneeType | String | Assignee type (User/Role). |
| Gra.Incidents.anomalies.riskScore | Number | Risk score for anomaly. |
| Gra.Incidents.anomalies.riskAcceptedDate | Date | Risk accepted date of anomaly. |
Command Example#
!gra-incidents status="OPEN" page=1 max=25
Context Example#
Human Readable Output#
gra-incident-action#
Close a GRA incident and update anomaly status as Closed / Risk Managed / Model Reviewed.
Base Command#
gra-incident-action
Input#
| Argument Name | Description | Required |
|---|---|---|
| action | Action (closeIncident, modelReviewIncident, riskManageIncident). | Required |
| incidentId | Incident Id. | Required |
| subOption | Sub Option. | Required |
| incidentComment | Incident Comment. | Required |
| riskAcceptDate | Risk Accept Date in yyyy-MM-dd format (riskManageIncident only). | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Incident.Action.Message | String | Message. |
Command Example#
!gra-incident-action action=closeIncident incidentId=5 subOption="True Incident" incidentComment="Closed from Cortex"
Context Example#
Human Readable Output#
gra-incident-action-anomaly#
Close anomalies within a GRA incident.
Base Command#
gra-incident-action-anomaly
Input#
| Argument Name | Description | Required |
|---|---|---|
| action | Action (closeIncidentAnomaly, modelReviewIncidentAnomaly, riskAcceptIncidentAnomaly). | Required |
| incidentId | Incident Id. | Required |
| anomalyNames | Anomaly Names. | Required |
| subOption | Sub Option. | Required |
| incidentComment | Incident Comment. | Required |
| riskAcceptDate | Risk Accept Date in yyyy-MM-dd format (riskAcceptIncidentAnomaly only). | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Incident.Action.Anomaly.Message | String | Message. |
Command Example#
!gra-incident-action-anomaly action=closeIncidentAnomaly incidentId=5 anomalyNames=anomalyName1 subOption="True Incident" incidentComment="Done"
Context Example#
Human Readable Output#
gra-incidents-anomaly#
Retrieve anomalies for a specified GRA incident id.
Base Command#
gra-incidents-anomaly
Input#
| Argument Name | Description | Required |
|---|---|---|
| incidentId | GRA Incident Id. | Required |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Incidents.anomalies.anomalyName | String | Incident Anomaly name. |
| Gra.Incidents.anomalies.status | String | Current status of anomaly. |
| Gra.Incidents.anomalies.datasourcename | String | Data Source Name. |
| Gra.Incidents.anomalies.assignee | String | Assignee name. |
| Gra.Incidents.anomalies.assigneeType | String | Assignee type (User/Role). |
| Gra.Incidents.anomalies.riskScore | Number | Risk score for anomaly. |
| Gra.Incidents.anomalies.riskAcceptedDate | Date | Risk accepted date of anomaly. |
Command Example#
!gra-incidents-anomaly incidentId=10
Context Example#
Human Readable Output#
gra-alerts#
Retrieve list of GRA alerts for a specified status and date range.
Base Command#
gra-alerts
Input#
| Argument Name | Description | Required |
|---|---|---|
| status | Status (OPEN, CLOSED, IN PROGRESS, ALL). | Required |
| startDate | Start Date (yyyy-MM-dd HH:mm:ss). | Required |
| endDate | End Date (yyyy-MM-dd HH:mm:ss). | Required |
| page | Page no. | Optional |
| max | Per page record count | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Alerts.alertId | Number | Alert Id. |
| Gra.Alerts.anomalyName | String | Anomaly Name. |
| Gra.Alerts.entityId | Number | Entity Id. |
| Gra.Alerts.entityTypeId | Number | Entity Type Id. |
| Gra.Alerts.entity | String | Entity. |
| Gra.Alerts.statusName | String | Status. |
| Gra.Alerts.detectionTimestamp | Date | Detection Timestamp. |
| Gra.Alerts.severity | Number | Severity. |
| Gra.Alerts.datasourcename | String | Data Source Name. |
| Gra.Alerts.riskScore | Number | Risk Score. |
| Gra.Alerts.graweblink | String | GRA Weblink. |
| Gra.Alerts.incidentType | String | Incident Type. |
| Gra.Alerts.assigneeIds | String | Assignee Ids. |
| Gra.Alerts.assigneeType | String | Assignee Type. |
| Gra.Alerts.assignee | String | Assignee. |
| Gra.Alerts.classifierList | String | Classifier List. |
| Gra.Alerts.subStatusName | String | Sub Status Name. |
Command Example#
!gra-alerts status="OPEN" startDate="2026-01-01 00:00:00" endDate="2026-12-31 23:59:59" page=1 max=25
Context Example#
Human Readable Output#
gra-alert-get#
Retrieve a single GRA alert by id.
Base Command#
gra-alert-get
Input#
| Argument Name | Description | Required |
|---|---|---|
| id | Alert Id. | Required |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Alert.alertId | Number | Alert Id. |
| Gra.Alert.anomalyName | String | Anomaly Name. |
| Gra.Alert.entityId | Number | Entity Id. |
| Gra.Alert.entityTypeId | Number | Entity Type Id. |
| Gra.Alert.entity | String | Entity. |
| Gra.Alert.statusName | String | Status. |
| Gra.Alert.detectionTimestamp | Date | Detection Timestamp. |
| Gra.Alert.severity | Number | Severity. |
| Gra.Alert.datasourcename | String | Data Source Name. |
| Gra.Alert.riskScore | Number | Risk Score. |
| Gra.Alert.graweblink | String | GRA Weblink. |
| Gra.Alert.incidentType | String | Incident Type. |
| Gra.Alert.assigneeIds | String | Assignee Ids. |
| Gra.Alert.assigneeType | String | Assignee Type. |
| Gra.Alert.assignee | String | Assignee. |
| Gra.Alert.classifierList | String | Classifier List. |
| Gra.Alert.subStatusName | String | Sub Status Name. |
| Gra.Alert.analyticalFeatures | String | Analytical Features. |
| Gra.Alert.analyticalFeatureValues | String | Analytical Feature Values. |
Command Example#
!gra-alert-get id=101
Context Example#
Human Readable Output#
gra-alert-action#
Perform an action on a GRA alert (close, assign, in progress, comment).
Base Command#
gra-alert-action
Input#
| Argument Name | Description | Required |
|---|---|---|
| action | Action (closeAlert, inProgressAlert, assignAlert, addCommentOnAlert). | Required |
| alertId | Alert Id. | Required |
| alertComment | Alert Comment. | Required |
| incidentType | Incident or Not An Incident (closeAlert). | Optional |
| subStatus | Close sub-status (closeAlert). | Optional |
| assigneeType | Assignee type (assignAlert). | Optional |
| assigneeName | Assignee name (assignAlert). | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Alert.Action.Message | String | Message. |
Command Example#
!gra-alert-action action=closeAlert alertId=101 alertComment="Closed" incidentType="Incident" subStatus="True Positive"
Context Example#
Human Readable Output#
gra-alert-comment#
Add a comment on a GRA alert (thin wrapper for addCommentOnAlert).
Base Command#
gra-alert-comment
Input#
| Argument Name | Description | Required |
|---|---|---|
| alertId | Alert Id. | Required |
| alertComment | Alert Comment. | Required |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Alert.Action.Message | String | Message. |
Command Example#
!gra-alert-comment alertId=101 alertComment="Investigating"
Context Example#
Human Readable Output#
gra-alert-assign#
Assign a GRA alert (thin wrapper for assignAlert).
Base Command#
gra-alert-assign
Input#
| Argument Name | Description | Required |
|---|---|---|
| alertId | Alert Id. | Required |
| assigneeType | Assignee type. | Required |
| assigneeName | Assignee name. | Required |
| alertComment | Alert Comment. | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Alert.Action.Message | String | Message. |
Command Example#
!gra-alert-assign alertId=101 assigneeType=GRA_USER assigneeName="Yuki.Jacob" alertComment="Assigning via XSOAR"
Context Example#
Human Readable Output#
gra-alert-in-progress#
Mark a GRA alert in progress (thin wrapper for inProgressAlert).
Base Command#
gra-alert-in-progress
Input#
| Argument Name | Description | Required |
|---|---|---|
| alertId | Alert Id. | Required |
| alertComment | Alert Comment. | Optional |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Alert.Action.Message | String | Message. |
Command Example#
!gra-alert-in-progress alertId=101 alertComment="Working this alert"
Context Example#
Human Readable Output#
gra-alert-update-history#
Retrieve update history for a GRA alert.
Base Command#
gra-alert-update-history
Input#
| Argument Name | Description | Required |
|---|---|---|
| alertId | Alert Id. | Required |
Context Output#
| Path | Type | Description |
|---|---|---|
| Gra.Alert.History.count | Number | Number of history entries. |
| Gra.Alert.History.alertDetails | String | Alert history details. |
| Gra.Alert.History.alertDetails.firstName | String | First name. |
| Gra.Alert.History.alertDetails.lastName | String | Last name. |
| Gra.Alert.History.alertDetails.addedDate | Date | Added date. |
| Gra.Alert.History.alertDetails.eventBy | String | Event by. |
| Gra.Alert.History.alertDetails.addedBy | String | Added by. |
| Gra.Alert.History.alertDetails.id | Number | History entry id. |
| Gra.Alert.History.alertDetails.profilePicturePath | String | Profile picture path. |
| Gra.Alert.History.alertDetails.actionName | String | Action name. |
| Gra.Alert.History.alertDetails.comment | String | Comment. |
Command Example#
!gra-alert-update-history alertId=101
Context Example#
Human Readable Output#
gra-validate-api#
Verifies the Gurucul platform's operational status by assessing system health, reviewing logs, and checking key performance indicators for any errors.
Base Command#
gra-validate-api
Command Example#
!gra-validate-api