Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

API endpoint to get SCRAM history #28

Open
netops2devops opened this issue Jan 19, 2024 · 0 comments
Open

API endpoint to get SCRAM history #28

netops2devops opened this issue Jan 19, 2024 · 0 comments
Labels
enhancement New feature or request

Comments

@netops2devops
Copy link

It would be useful if there was a way to be able to query SCRAM (over WebUI and API endpoint) to check if it has previously blocked an {{IP_ADDR}} that is being investigated either by an analyst or by a SOAR workflow.

Things we care about in response object:

  • IP Address
  • currently blocked (yes or no)
  • Previously seen (yes or no)
  • Last block date
  • how many times it has blocked in the past
  • comments (if any)
@netops2devops netops2devops added the enhancement New feature or request label Jan 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Status: Backlog
Development

No branches or pull requests

1 participant