<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Orbital Scripts API in Integrated Security Platform</title>
    <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4947602#M903</link>
    <description>&lt;P&gt;I'm looking for documentation on using the Orbital API to run Orbital scripts.&amp;nbsp; I find plenty of documentation on querying the Orbital API, but I'm not finding anything on using the new Orbital scripts feature.&amp;nbsp; I see some indications that it may be accessible using GraphQL, but I don't see any documentation on it and I haven't been able to locate the GraphQL endpoint for Orbital.&lt;/P&gt;&lt;P&gt;The purpose of this is to eventually add this to an existing SecureX orchestration we have that posts information in a Webex space when a machine is isolated.&amp;nbsp; I have an Orbital script that splashes a nice notification on an endpoint letting the user know that their PC has been isolated, etc. and this works well, however, I am not able to run the script through orchestration.&lt;/P&gt;&lt;P&gt;Am I missing something obvious?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2023 10:48:01 GMT</pubDate>
    <dc:creator>Flint</dc:creator>
    <dc:date>2023-10-25T10:48:01Z</dc:date>
    <item>
      <title>Orbital Scripts API</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4947602#M903</link>
      <description>&lt;P&gt;I'm looking for documentation on using the Orbital API to run Orbital scripts.&amp;nbsp; I find plenty of documentation on querying the Orbital API, but I'm not finding anything on using the new Orbital scripts feature.&amp;nbsp; I see some indications that it may be accessible using GraphQL, but I don't see any documentation on it and I haven't been able to locate the GraphQL endpoint for Orbital.&lt;/P&gt;&lt;P&gt;The purpose of this is to eventually add this to an existing SecureX orchestration we have that posts information in a Webex space when a machine is isolated.&amp;nbsp; I have an Orbital script that splashes a nice notification on an endpoint letting the user know that their PC has been isolated, etc. and this works well, however, I am not able to run the script through orchestration.&lt;/P&gt;&lt;P&gt;Am I missing something obvious?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 10:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4947602#M903</guid>
      <dc:creator>Flint</dc:creator>
      <dc:date>2023-10-25T10:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Orbital Scripts API</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4947663#M904</link>
      <description>No.&lt;BR /&gt;&lt;BR /&gt;Pretty sure that specific piece hasn't been released yet.  The API docs were not ready during the beta, and there were some discussions of tweaking the API some more before releasing it.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 25 Oct 2023 11:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4947663#M904</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-10-25T11:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Orbital Scripts API</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4947665#M905</link>
      <description>&lt;P&gt;Thanks for the info, Ken!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 11:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4947665#M905</guid>
      <dc:creator>Flint</dc:creator>
      <dc:date>2023-10-25T11:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Orbital Scripts API</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4963837#M918</link>
      <description>&lt;P&gt;Hi Flint (and Ken),&lt;/P&gt;
&lt;P&gt;Apologies for the delay while we sorted some technical issues, but we've just recently moved our API documentation to&amp;nbsp;&lt;A href="https://developer.cisco.com/docs/orbital/" target="_blank"&gt;https://developer.cisco.com/docs/orbital/&lt;/A&gt;&amp;nbsp; and also added the documentation for the new Orbital Script APIs there as well. Please take a look!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 16:16:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4963837#M918</guid>
      <dc:creator>eugechan</dc:creator>
      <dc:date>2023-11-21T16:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Orbital Scripts API</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4966726#M920</link>
      <description>&lt;P&gt;Thank you, eugechan!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 10:41:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/4966726#M920</guid>
      <dc:creator>Flint</dc:creator>
      <dc:date>2023-11-27T10:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Orbital Scripts API</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/5101441#M949</link>
      <description>&lt;P&gt;I am a bit confused on the Orbital Script API document.&amp;nbsp; I am hoping it is like using the Query body syntax where I can give it the name of the Script ("&lt;SPAN&gt;windows_exec_powershell_cmdlets" in this case) along with its arguments.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;import requests
import json

url = "https://orbital.amp.cisco.com/v0/script/run"

payload = json.dumps({
  "name": "Execute Powershell Cmdlet",
  "nodes": [
    "amp:235bxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
  ],
  "expiry": 1715368484,
  "interval": 0,
  "stock": "windows_exec_powershell_cmdlets",
  "stockArgs": {
    "cmdlet": [
      "Get-Date"
    ]
  }
})
headers = {
  'Content-Type': 'application/json',
  'Authorization': 'Bearer &amp;lt;token&amp;gt;'
}

response = requests.request("POST", url, headers=headers, data=payload)

print(response.text)&lt;/LI-CODE&gt;&lt;LI-CODE lang="javascript"&gt;{
    "errors": [
        "access to this feature is not permitted"
    ]
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 20:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/5101441#M949</guid>
      <dc:creator>TomML</dc:creator>
      <dc:date>2024-05-10T20:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Orbital Scripts API</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/5103767#M950</link>
      <description>&lt;P&gt;Hi TomML,&lt;/P&gt;
&lt;P&gt;Thanks for the post.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a security measure, Orbital scripts are only able to be executed by users and API clients that have the Admin role.&lt;/P&gt;
&lt;P&gt;Unfortunately, you cannot modify API clients in SecureX after they have been created, so you will need to generate a new one in order to execute Scripts via API. Please ensure that you have both the "Admin" and "Orbital" options selected when generating the new API client.&lt;/P&gt;
&lt;P&gt;Once you have the new API client generated please try your API call again and see if it works!&lt;/P&gt;
&lt;P&gt;Reviewing the documentation, I see that this isn't clearly explained, so I'll look to get that added so that others don't encounter the same issue.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 16:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/5103767#M950</guid>
      <dc:creator>eugechan</dc:creator>
      <dc:date>2024-05-13T16:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Orbital Scripts API</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/5103935#M951</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/553921"&gt;@eugechan&lt;/a&gt;&amp;nbsp;,&amp;nbsp; I created a new API client with Admin and Orbital options.&amp;nbsp; I think I am making progress - I'll further review the API documentation.&amp;nbsp; Appreciate your feedback!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;import requests
import json

url = "https://orbital.amp.cisco.com/v0/script/run"
payload = json.dumps({
  "name": "Execute Powershell Cmdlet",
  "nodes": [
    "amp:235bxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
  ],
  "expiry": 1715642962,
  "interval": 0,
  "stock": "windows_exec_powershell_cmdlets",
  "stockArgs": {
    "cmdlet": [
      "Get-Date"
    ]
  }
})
headers = {
  'Content-Type': 'application/json',
  'Authorization': 'Bearer &amp;lt;token&amp;gt;'
}

response = requests.request("POST", url, headers=headers, data=payload)

print(response.text)

{
    "errors": [
        "neither field for scriptContent and catalog_id exists"
    ]
}&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;I did swap out&amp;nbsp;&lt;SPAN&gt;scriptContent for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;catalog_id but same error (400 Bad Request).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 23:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/5103935#M951</guid>
      <dc:creator>TomML</dc:creator>
      <dc:date>2024-05-13T23:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Orbital Scripts API</title>
      <link>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/5103937#M952</link>
      <description>&lt;P&gt;Nevermind - I got it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;import requests
import json

url = "https://orbital.amp.cisco.com/v0/script/run"

payload = json.dumps({
  "name": "Execute Powershell Cmdlet via API",
  "nodes": [
    "amp:235xxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
  ],
  "expiry": 1715643679,
  "interval": 0,
  "script": {
    "args": [
      {
        "Name": "cmdlet",
        "Value": "Get-Date"
      }
    ],
    "catalog_id": "windows_exec_powershell_cmdlets"
  }
})
headers = {
  'Content-Type': 'application/json',
  'Authorization': 'Bearer &amp;lt;token&amp;gt;'
}

response = requests.request("POST", url, headers=headers, data=payload)

print(response.text)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 23:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/integrated-security-platform/orbital-scripts-api/m-p/5103937#M952</guid>
      <dc:creator>TomML</dc:creator>
      <dc:date>2024-05-13T23:44:41Z</dc:date>
    </item>
  </channel>
</rss>

