Releases: code42/incydr_python
Releases · code42/incydr_python
v2.2.0
2.2.0 - 2024-11-18
Updated
- Updated the
FileEventV2model to all existing fields at this time. For example, the recently addedresponseControlsresponse object is now available on the model. - Updated
EventQueryobjects to allow filtering by any string by removing the requirement that filter terms and values must match explicitly defined fields. This allows end users to filter by fields recently added to the file event response without requiring an SDK update. client.actors.v1.get_actor_by_namenow defaults toprefer_parent=True. Previously, it defaulted toFalse.
v2.1.0
2.1.0 - 2024-09-30
Added
- Support for the API to update actors.
client.actors.v1.update_actor- to update an actor's start date, end date, or notes.
- A CLI command to update an actor.
incydr actors update- to update an actor's start date, end date, or notes.
Deprecated
- Risk Profiles methods and commands are now deprecated, replaced by the
actorscommand group.
v2.0.0
2.0.0 - 2024-05-10
Added
- Support for the Sessions APIs
- A
sessions.v1client to the SDK with the following methods:client.sessions.v1.get_page()- to query a page of sessions.client.sessions.v1.iter_all()- to lazily iterate through all pages of sessions.client.sessions.v1.get_session_details()- to retrieve the details of a single session specified by ID.client.sessions.v1.get_session_events()- to retrieve the file events associated with a session specified by ID.client.sessions.v1.update_state_by_id()- to update the state of a session specified by ID.client.sessions.v1.update_state_by_criteria()- to update the state of all sessions matching the filter criteria.client.sessions.v1.add_note()- to attach a note to a session specified by ID.
- A set of
sessionsCLI commands:incydr sessions searchto search sessions by criteria. Includes various filter, output, and checkpointing options.incydr sessions showto show session details.incydr sessions show-eventsto show file events associated with the session.incydr sessions updateto update the state and/or note of a session.incydr sessions bulk-update-stateto update the state and attach an optional note to multiple sessions at once
- A
- Support for Actors APIs, including:
- An
actors.v1client to the SDK with the following methods:client.actors.v1.get_page()- to query a single page of actors.client.actors.v1.iter_all()- to lazily iterate through all pages of actors.client.actors.v1.get_actor_by_id()- to retrieve details of a single actor by ID.client.actors.v1.get_actor_by_name()- to retrieve details of a single actor by name.client.actors.v1.get_family_by_member_id()- to retrieve details of an actor family by a member's ID.client.actors.v1.get_family_by_member_name()- to retrieve details of an actor family by a member's name.
- A set of
actorsCLI commands:incydr actors listto list all actors matching search criteria (in table, CSV, or JSON formats).incydr actors showto show details of a given actor by ID or name.incydr actors show-familyto show details of an actors family.
- An
Removed
- Breaking Change! Cloud alias risk profile functionality has been removed.
- The following Python SDK methods have been removed:
client.user_risk_profiles.add_cloud_alias()should be replaced byclient.actors.create_adoption()client.user_risk_profiles.remove_cloud_alias()should be replaced byclient.actors.remove_adoption()
- The following CLI commands have been removed.
incydr risk-profiles add-cloud-aliasshould be replaced byincydr actors adoption createincydr risk-profiles remove-cloud-aliasshould be replaced byincydr actors adoption removeincydr risk-profiles bulk-add-cloud-aliasesincydr risk-profiles bulk-remove-cloud-aliases
- The following Python SDK methods have been removed:
Changed
- Breaking Change!
User risk profileshave been renamed asRisk profilesto better fit their additional application to actors.- The SDK has been updated to reflect this via the following changes:
UserRiskProfilemodel has been renamed toRiskProfile.UserRiskProfilesPagemodel has been renamed toRiskProfilesPage.- The
UserRiskProfilesclass has been renamed toRiskProfiles - The Incydr client
user_risk_profilesproperty has been renamed torisk_profiles, methods in that client have been renamed similarly.client.user_risk_profiles.v1.get_user_risk_profile()would now beclient.risk_profiles.v1.get_risk_profile().
- The CLI has been updated to reflect this via the following changes:
- The
risk-profilescommand group is no longer available under theuserscommand group. It is still accessible as its ownincydrcommand group. ex:incydr risk-profiles list.
- The
- The SDK has been updated to reflect this via the following changes:
Deprecated
- Alerts Python SDK methods and the Alerts CLI commands group have been deprecated. Functionality is replaced by the Sessions SDK client and CLI command group.
v1.2.0
1.2.0 - 2024-3-18
Added
- The following agent health related fields will be present on the response when retrieving agents:
serialNumbermachineIdagentHealthIssueTypes
- Additional optional args in the SDK's agent client for filtering by agent health.
client.agents.v1.get_page()andclient.agents.v1.get_page()now accept:agent_healthy: bool- Retrieve only healthy agents withTrueor only unhealthy agents withFalse. Defaults to returning all agents.agent_health_issue_types: List[str] | str- Retrieve agents with any of the given health issues. Ex:NOT_CONNECTING
- Additional options in the CLI's agent command group for filtering by agent health:
incydr agents listnow accepts:--healthy- Retrieve only healthy agents.--unhealthy- Retrieve only unhealthy agents.- Pass a comma separated list of health issue types to the unhealthy option to filter for agents with any of the given health issues. Ex:
--unhealthy NOT_CONNECTING,NOT_SENDING_SECURITY_EVENTS - Use
incydr agents list --helpto see more specifics on the new command options.
- See the SDK documentation and the CLI documentation for more details.
v1.1.2
1.1.2 - 2023-12-11
Fixed
- Saved search filter values can now accept a list of strings. Prior to this fix this was incorrectly resulting in a model validation error.
v1.1.1
1.1.1 - 2023-10-03
Fixed
- Pinned Pydantic version to major version
1.*following the release of Pydantic 2.0.
v1.1.0
1.1.0 - 2023-05-01
Added
- Better error messaging when authentication parameters or env vars missing when instantiating the
incydr.Clientor running CLI commands. - Missing authentication parameters (
url,api_client_id, orapi_client_secret) causes client to raise new exception type:AuthMissingError. incydr.exceptionsmodule has been added to the public API.- Support for Agents APIs, including:
- An
agents.v1client to the SDK with the following methods:client.agents.v1.get_page()to query a single page of agents.client.agents.v1.iter_all()to lazily iterate through all pages of agents.client.agents.v1.get_agent()to retrieve details of a single agent by ID.client.agents.v1.update()to update thenameorexternalReferencefield of an agent.client.agents.v1.activate()to activate a list of agents by their IDs.client.agents.v1.deactivate()to deactivate a list of agents by their IDs.
- A set of
agentsCLI commands:incydr agents listto list all agents in your environment (in table, CSV, or JSON formats).incydr agents showto show the details of a given agent by ID.incydr agents bulk-activateto activate a set of agents from CSV or JSON-LINES file input.incydr agents bulk-deactivateto deactivate a set of agents from CSV or JSON-LINES file input.
- An
- New search terms on the incydr.enums.file_events.EventSearchTerm enum, enabling full support for querying the latest file event fields.
- New file event field models:
AcquiredFromGit,AcquiredFromSourceUser,UntrustedValues. - Various other additions to existing model fields