Skip to content

Supported CEL Macros๐Ÿ”—

Note

The terms Alerts and Investigations have recently been changed to Detections and Cases in Taegis XDR. You may still see references to the old terms while we continue to work towards platform convergence of Sophos and Taegis technologies. For more information, see Taegis Terminology Updates.

The Secureworksยฎ Taegisโ„ข XDR Automations platform can use Googleโ€™s Common Expression Language (CEL) to enable embedding logic and data manipulation within connectors, playbook inputs, playbook triggers, and templates.

XDR supports a number of Googleโ€™s Common Expression Language (CEL) macros that allow you to manipulate and evaluate data. Many macros are built-in, but some have been custom built to address common problems.

In these examples, the following data structure is used:

{
    "plant": {
        "type": "tree",
        "name": "white oak",
        "uses": [
            "lumber",
            "firewood",
            "furniture"
        ],
        "traits": {
            "produces_fruit": yes,
            "genus": "Quercus",
            "height": 100,
            "extinct": false,
            "related_to": [
                {
                    "name": "chestnut",
                    "genus": "Castanea"
                },
                {
                    "name": "beech",
                    "genus": "Fagus"
                }
           ]
        },
        "locations": [
            "usa",
            "europe",
            "new york",
            "New York",
            "new york  ",
            "usa",
            "worldwide",
            "eu"
        ]
    }
}

Available macros๐Ÿ”—

? (optional operator)๐Ÿ”—

? is an optional operator for safe navigation, safe indexing, and conditional inclusion in CEL expressions.

The ? operator provides the following capabilities:

  • Safe field navigation (obj.?field): Access fields without errors.
  • Safe map indexing (map[?key]): Access map values safely.
  • Safe list indexing (list[?index]): Access list elements safely.
  • Optional map fields ({?key: value}): Conditionally include map fields.
  • Optional list elements ([?element]): Conditionally include list elements.

After the first ? operator, subsequent accesses are automatically safe (viral chaining): obj.?field.subfield == obj.?field.?subfield.

Notes๐Ÿ”—

  • The ? operator returns optional values that need .orValue() or .hasValue().
  • Safe navigation never throws errors on missing fields, keys, or indices.
  • Optional field/element syntax requires optional-typed values.
  • Use with optional.of(), optional.none(), or optional.ofNonZeroValue().

Examples๐Ÿ”—

{'name': 'John'}.?name.orValue('Unknown')

{'name': 'John'}.?name.orValue('Unknown')

Output: 'John'

Safe field navigation.

{}.?name.orValue('Unknown')

{}.?name.orValue('Unknown')

Output: 'Unknown'

Field missing returns optional.none().

{'a': 1, 'b': 2}[?'a'].orValue(0)

{'a': 1, 'b': 2}[?'a'].orValue(0)

Output: 1

Safe map indexing.

{'a': 1}[?'c'].orValue(0)

{'a': 1}[?'c'].orValue(0)

Output: 0

Missing key returns optional.none().

[1, 2, 3][?0].orValue(0)

[1, 2, 3][?0].orValue(0)

Output: 1

Safe list indexing.

[1, 2, 3][?10].orValue(0)

[1, 2, 3][?10].orValue(0)

Output: 0

Out-of-bounds index returns optional.none().

{?'key': optional.of(5)}.size()

{?'key': optional.of(5)}.size()

Output: 1

Optional map field is included.

{?'key': optional.none()}.size()

{?'key': optional.none()}.size()

Output: 0

Optional map field is omitted.

[1, ?optional.of(2), 3].size()

[1, ?optional.of(2), 3].size()

Output: 3

Optional list element is included.

[1, ?optional.none(), 3].size()

[1, ?optional.none(), 3].size()

Output: 2

Optional list element is omitted.

abs๐Ÿ”—

Returns the absolute value of the provided argument.

Input and output๐Ÿ”—

abs(double) -> double
abs(int) -> int
abs(uint) -> uint

Examples๐Ÿ”—

abs(-1.0)

abs(-1.0)

Output: 1.0

abs(1.0)

abs(1.0)

Output: 1.0

alertAttackTechniqueIds๐Ÿ”—

Parses an alert record and returns the attack technique IDs value.

Input and output๐Ÿ”—

alertAttackTechniqueIds(map) -> list

Examples๐Ÿ”—

alertAttackTechniqueIds(inputs)

alertAttackTechniqueIds(inputs)

Output: ["T1096", "T1214"]

alertConfidence๐Ÿ”—

Parses an alert record and returns the confidence value.

Input and output๐Ÿ”—

alertConfidence(map) -> double

Examples๐Ÿ”—

alertConfidence(inputs)

alertConfidence(inputs)

Output: 0.5

alertCreatedAtNanos๐Ÿ”—

Parses an alert record and returns the nanoseconds value of the time the alert was created.

Input and output๐Ÿ”—

alertCreatedAtNanos(map) -> int

Examples๐Ÿ”—

alertCreatedAtNanos(inputs)

alertCreatedAtNanos(inputs)

Output: 796357058

alertCreatedAtSeconds๐Ÿ”—

Parses an alert record and returns the created_at value as a measure of seconds from epoch.

Input and output๐Ÿ”—

alertCreatedAtSeconds(map) -> int

Examples๐Ÿ”—

alertCreatedAtSeconds(inputs)

alertCreatedAtSeconds(inputs)

Output: 1636029855

alertDescription๐Ÿ”—

Parses an alert record and returns the description value.

Input and output๐Ÿ”—

alertDescription(map) -> string

Examples๐Ÿ”—

alertDescription(inputs)

alertDescription(inputs)

Output: "This is a sample Taegis Watchlist Alert"

alertDestinationIPs๐Ÿ”—

Parses an alert record and returns a unique list of IP address values from the alert entities field where the entity is labeled destinationIPAddress (case insensitive).

Input and output๐Ÿ”—

alertDestinationIPs(map) -> list

Examples๐Ÿ”—

alertDestinationIPs(inputs)

alertDestinationIPs(inputs)

Output: ["192.168.0.1", "192.168.0.2"]

alertDetectorId๐Ÿ”—

Parses an alert record and returns the detector ID value.

Input and output๐Ÿ”—

alertDetectorId(map) -> string

Examples๐Ÿ”—

alertDetectorId(inputs)

alertDetectorId(inputs)

Output: "app:event-filter"

alertDetectorName๐Ÿ”—

Parses an alert record and returns the detector name value.

Input and output๐Ÿ”—

alertDetectorName(map) -> string

Examples๐Ÿ”—

alertDetectorName(inputs)

alertDetectorName(inputs)

Output: "Taegis Watchlist"

alertDomains๐Ÿ”—

Parses an alert record and returns a unique list of domain name values from the alert entities field where the entity is labeled ipdomain, topprivateipdomain, domainname, authdomainname, sourceauthdomainname, or targetauthdomainname (case insensitive).

Input and output๐Ÿ”—

alertDomains(map) -> list

Examples๐Ÿ”—

alertDomains(inputs)

alertDomains(inputs)

Output: ["example.com", "a.example.com"]

alertEnrichment๐Ÿ”—

Parses an alert record and the enrichment data and returns the first value matching the path provided.

Input and output๐Ÿ”—

alertEnrichment(map, string) -> any

Examples๐Ÿ”—

alertEnrichment(inputs, 'rare_program_rare_ip.programs')

alertEnrichment(inputs, 'rare_program_rare_ip.programs')

Output: ["foo.exe", "bar.exe"]

alertEnrichment(inputs, 'doesnotexist')

alertEnrichment(inputs, 'doesnotexist')

Output: []

alertEntities๐Ÿ”—

Parses an alert record and returns the entities value.

Input and output๐Ÿ”—

alertEntities(map) -> list

Examples๐Ÿ”—

alertEntities(inputs)

alertEntities(inputs)

Output: ["hostname:abc", "sensorId:12345", "fileName:c:\windows\syswow64\cmd.exe"]

alertEntity๐Ÿ”—

Parses an alert record and returns the entity values that match the provided entity name (case insensitive).

Input and output๐Ÿ”—

alertEntity(map, string) -> list

Examples๐Ÿ”—

alertEntity(inputs, 'username')

alertEntity(inputs, 'username')

Output: ["sample_user","another_sample_user"]

alertEventIds๐Ÿ”—

Parses an alert record and returns a list of event ID values.

Input and output๐Ÿ”—

alertEventIds(map) -> list

Examples๐Ÿ”—

alertEventIds(inputs)

alertEventIds(inputs)

Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

alertGroupKey๐Ÿ”—

Parses an alert record and returns the group_key value.

Input and output๐Ÿ”—

alertGroupKey(map) -> string

Examples๐Ÿ”—

alertGroupKey(inputs)

alertGroupKey(inputs)

Output: "12345:app:event-filter:80c0809b-153f-4b81-bb7c-52fcb83c7127"

alertHostnames๐Ÿ”—

Parses an alert record and returns a unique list of values from the alert entities field where the entity is labeled hostname, sourcehostname, desthostname, workstationname, or computername (case insensitive).

Input and output๐Ÿ”—

alertHostnames(map) -> list

Examples๐Ÿ”—

alertHostnames(inputs)

alertHostnames(inputs)

Output: ["sample_hostname", "another_sample_hostname"]

alertIPs๐Ÿ”—

Parses an alert record and returns a unique list of IP address values from the alert entities field where the entity is labeled ipAddress (case insensitive).

Input and output๐Ÿ”—

alertIPs(map) -> list

Examples๐Ÿ”—

alertIPs(inputs)

alertIPs(inputs)

Output: ["192.168.0.1", "192.168.0.2"]

alertId๐Ÿ”—

Parses an alert record and returns the ID or UUID.

Input and output๐Ÿ”—

alertId(map) -> string

Examples๐Ÿ”—

alertId(inputs)

alertId(inputs)

Output: "alert://priv:endpoint-redcloak:12345:1678899090095:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"

alertInvestigationIds๐Ÿ”—

Parses an alert record and returns a list of investigation IDs associated with the alert.

Input and output๐Ÿ”—

alertInvestigationIds(map) -> list

Examples๐Ÿ”—

alertInvestigationIds(inputs)

alertInvestigationIds(inputs)

Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

alertMitreAttackInfo๐Ÿ”—

Parses an alert record and returns a list of mitre_attack_info values.

Input and output๐Ÿ”—

alertMitreAttackInfo(map) -> list

Examples๐Ÿ”—

alertMitreAttackInfo(inputs)

alertMitreAttackInfo(inputs)

Output: [{"description":"Adversaries may attempt...","technique":"Process Discovery","technique_id":"T1057"}]

alertObservationIds๐Ÿ”—

Parses an alert record and returns a list of observation ID values.

Input and output๐Ÿ”—

alertObservationIds(map) -> list

Examples๐Ÿ”—

alertObservationIds(inputs)

alertObservationIds(inputs)

Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

alertReferences๐Ÿ”—

Parses an alert record and returns a list of references associated with the alert.

Input and output๐Ÿ”—

alertReferences(map) -> list

Examples๐Ÿ”—

alertReferences(inputs)

alertReferences(inputs)

Output: [{"description": "External Alert Ref","url": "https://example.com/alert/29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"}]

alertResolution๐Ÿ”—

Parses an alert record and returns the resolution value.

Input and output๐Ÿ”—

alertResolution(map) -> string

Examples๐Ÿ”—

alertResolution(inputs)

alertResolution(inputs)

Output: "open"

alertResolutionReason๐Ÿ”—

Parses an alert record and returns the resolution reason value.

Input and output๐Ÿ”—

alertResolutionReason(map) -> string

Examples๐Ÿ”—

alertResolutionReason(inputs)

alertResolutionReason(inputs)

Output: "Valid activity for this user."

alertRuleId๐Ÿ”—

Parses an alert record and returns the rule ID.

Input and output๐Ÿ”—

alertRuleId(map) -> string

Examples๐Ÿ”—

alertRuleId(inputs)

alertRuleId(inputs)

Output: "267658fe-65f1-4145-8753-d45fbf9ed6d3"

alertSensorIds๐Ÿ”—

Parses an alert record and returns a list of sensor ID values.

Input and output๐Ÿ”—

alertSensorIds(map) -> list

Examples๐Ÿ”—

alertSensorIds(inputs)

alertSensorIds(inputs)

Output: ["12345", "1234-12345-123"]

alertSensorTypes๐Ÿ”—

Parses an alert record and returns a list of unique sensor type values (in uppercase).

Input and output๐Ÿ”—

alertSensorTypes(map) -> list

Examples๐Ÿ”—

alertSensorTypes(inputs)

alertSensorTypes(inputs)

Output: ["ENDPOINT_REDCLOAK", "ENDPOINT_TAEGIS"]

alertSeverity๐Ÿ”—

Parses an alert record and returns the severity value.

Input and output๐Ÿ”—

alertSeverity(map) -> double

Examples๐Ÿ”—

alertSeverity(inputs)

alertSeverity(inputs)

Output: 0.75

alertSeverityNice๐Ÿ”—

Parses an alert record and returns the human-friendly severity value as a word (Informational, Low, Medium, High, Critical).

Input and output๐Ÿ”—

alertSeverityNice(map) -> string

Examples๐Ÿ”—

alertSeverityNice(inputs)

alertSeverityNice(inputs)

Output: "High"

alertSourceIPs๐Ÿ”—

Parses an alert record and returns a unique list of IP address values from the alert entities field where the entity is labeled sourceIPAddress (case insensitive).

Input and output๐Ÿ”—

alertSourceIPs(map) -> list

Examples๐Ÿ”—

alertSourceIPs(inputs)

alertSourceIPs(inputs)

Output: ["192.168.0.1", "192.168.0.2"]

alertStatus๐Ÿ”—

Parses an alert record and returns the status value.

Input and output๐Ÿ”—

alertStatus(map) -> string

Examples๐Ÿ”—

alertStatus(inputs)

alertStatus(inputs)

Output: "open"

alertTags๐Ÿ”—

Parses an alert record and returns a list of tags.

Input and output๐Ÿ”—

alertTags(map) -> list

Examples๐Ÿ”—

alertTags(inputs)

alertTags(inputs)

Output: ["alertRule:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "compactor:handler"]

alertTenantId๐Ÿ”—

Parses an alert record and returns the tenant ID.

Input and output๐Ÿ”—

alertTenantId(map) -> string

Examples๐Ÿ”—

alertTenantId(inputs)

alertTenantId(inputs)

Output: "12345"

alertThirdPartyDetail๐Ÿ”—

Parses an alert record and the third-party detail data and returns the first value matching the path provided.

Input and output๐Ÿ”—

alertThirdPartyDetail(map, string) -> list

Examples๐Ÿ”—

alertThirdPartyDetail(inputs, 'userStates.0.aadUserId')

alertThirdPartyDetail(inputs, 'userStates.0.aadUserId')

Output: ["F86DBD0D-6571-44A0-BAE1-43B83CF430AD"]

alertTitle๐Ÿ”—

Parses an alert record and returns the title value.

Input and output๐Ÿ”—

alertTitle(map) -> string

Examples๐Ÿ”—

alertTitle(inputs)

alertTitle(inputs)

Output: "Taegis Watchlist Alert"

alertUpdatedAtNanos๐Ÿ”—

Parses an alert record and returns the nanoseconds value of the time the alert was modified.

Input and output๐Ÿ”—

alertUpdatedAtNanos(map) -> int

Examples๐Ÿ”—

alertUpdatedAtNanos(inputs)

alertUpdatedAtNanos(inputs)

Output: 796357058

alertUpdatedAtSeconds๐Ÿ”—

Parses an alert record and returns the updated_at value as a measure of seconds from epoch.

Input and output๐Ÿ”—

alertUpdatedAtSeconds(map) -> int

Examples๐Ÿ”—

alertUpdatedAtSeconds(inputs)

alertUpdatedAtSeconds(inputs)

Output: 1697207995554

alertUsernames๐Ÿ”—

Parses an alert record and returns a unique list of lowercase username values from the alert entities field where the entity is labeled username (case insensitive).

Input and output๐Ÿ”—

alertUsernames(map) -> list

Examples๐Ÿ”—

alertUsernames(inputs)

alertUsernames(inputs)

Output: ["sample_user", "another_sample_user"]

all๐Ÿ”—

Iterates on a list or map and validates that a condition is true for all elements in the list.

Input and output๐Ÿ”—

all(list, predicate) -> bool
all(map, predicate) -> bool

Examples๐Ÿ”—

[1,2,3,4].all(x, x > 0)

[1,2,3,4].all(x, x > 0)

Output: true

[1,2,3,0].all(x, x > 0)

[1,2,3,0].all(x, x > 0)

Output: false

append๐Ÿ”—

Adds elements to an existing list.

Input and output๐Ÿ”—

append(list, any) -> list

Examples๐Ÿ”—

append([1, 2, 3], 4)

append([1, 2, 3], 4)

Output: [1, 2, 3, 4]

append([], "newElement")

append([], "newElement")

Output: ["newElement"]

assetTags๐Ÿ”—

Returns a list of asset tag key/value pairs from an asset. By default, returns both keys and values. Optionally returns only keys or values.

Input and output๐Ÿ”—

assetTags(map) -> list
assetTags(map, string) -> list

Examples๐Ÿ”—

assetTags(inputs)

assetTags(inputs)

Output: ["t1:v1", "t2:v2"]

assetTags(inputs, "keys")

assetTags(inputs, "keys")

Output: ["t1", "t2"]

assetTags(inputs, "values")

assetTags(inputs, "values")

Output: ["v1", "v2"]

base64.decode๐Ÿ”—

Decodes a base64-encoded string to bytes.

Input and output๐Ÿ”—

base64.decode(string) -> bytes

Decodes a base64-encoded string back to its original byte sequence.

Returns empty bytes for empty input.

The input must be a valid base64-encoded string.

Use cases๐Ÿ”—

Decode encoded credentials.

base64.decode('dXNlcm5hbWU6cGFzc3dvcmQ=')

Output: b'username:password'

Decode Basic Authentication credentials.

Convert to string.

string(base64.decode('aGVsbG8='))

Output: "hello"

Decode and convert bytes to a string.

Decode API responses.

string(base64.decode(api_response.encoded_data))

Decode base64-encoded API response data.

Validate encoding.

base64.decode(base64.encode(b'test'))

Output: b'test'

Verify round-trip encoding and decoding.

Process encoded input.

string(base64.decode(input.encoded_value))

Decode user-provided base64 input.

Empty input handling.

base64.decode('')

Output: b''

Empty string produces empty bytes.

Chain with string operations.

string(base64.decode('aGVsbG8=')).upperAscii()

Output: "HELLO"

Decode, convert to a string, then uppercase.

Working with JSON.

string(base64.decode('eyJrZXkiOiJ2YWx1ZSJ9'))

Output: '{"key":"value"}'

Decode base64-encoded JSON.

Error handling๐Ÿ”—

  • Invalid base64 strings will cause an error.
  • Padding characters (=) are handled automatically.
  • Whitespace in input may cause decoding errors.

Notes๐Ÿ”—

  • Input must be a valid base64-encoded string.
  • Output is always a bytes type.
  • Use string() conversion to get a string from bytes.
  • Uses standard base64 decoding (RFC 4648).
  • This coexists with the custom decodeBase64() function.

Common patterns๐Ÿ”—

Decode and use as string:

string(base64.decode(encoded_input))

Most common pattern: decode and convert to a string.

Decode and process:

cel.bind(decoded, base64.decode(input), decoded.size() > 0 ? string(decoded) : 'empty')

Decode, check size, then convert or return a default value.

Round trip validation:

string(base64.decode(base64.encode(b'test'))) == 'test'

Validate that encoding and decoding work correctly.

Examples๐Ÿ”—

base64.decode('aGVsbG8=')

base64.decode('aGVsbG8=')

Output: b'hello'

base64.decode('aGVsbG8gd29ybGQ=')

base64.decode('aGVsbG8gd29ybGQ=')

Output: b'hello world'

base64.decode('dGVzdDEyMw==')

base64.decode('dGVzdDEyMw==')

Output: b'test123'

base64.decode('')

base64.decode('')

Output: b''

base64.encode๐Ÿ”—

Encodes bytes to a base64-encoded string.

Input and output๐Ÿ”—

base64.encode(bytes) -> string

Encodes a byte sequence to a base64-encoded string using standard base64 encoding.

Returns an empty string for empty input.

The output is a URL-safe base64 string.

Use cases๐Ÿ”—

Encode text for transmission.

base64.encode(b'username:password')

Output: "dXNlcm5hbWU6cGFzc3dvcmQ="

Encode credentials for Basic Authentication.

Encode binary data.

base64.encode(file_content)

Convert binary file content to a text representation.

Data serialization.

base64.encode(b'{"key": "value"}')

Encode JSON data for URL parameters.

Safe string encoding.

base64.encode(b'data with special chars: !@#$%')

Encode strings containing special characters.

Round-trip encoding.

string(base64.decode(base64.encode(b'test')))

Output: "test"

Verify that encoding and decoding work correctly.

Working with string conversion.

base64.encode(bytes(input.text))

Convert a string to bytes, then encode.

Empty input handling.

base64.encode(b'')

Output: ""

Empty bytes produce an empty string.

Notes๐Ÿ”—

  • Input must be a bytes type. Use b'...' syntax or bytes() conversion.
  • Output is always a string.
  • Uses standard base64 encoding (RFC 4648).
  • Padding characters (=) are included as needed.
  • This coexists with the custom encodeBase64() function.

Examples๐Ÿ”—

base64.encode(b'hello')

base64.encode(b'hello')

Output: "aGVsbG8="

base64.encode(b'hello world')

base64.encode(b'hello world')

Output: "aGVsbG8gd29ybGQ="

base64.encode(b'test123')

base64.encode(b'test123')

Output: "dGVzdDEyMw=="

base64.encode(b'')

base64.encode(b'')

Output: ""

caseArchivedAt๐Ÿ”—

Parses a case record and returns the date and time it was archived.

Input and output๐Ÿ”—

caseArchivedAt(map) -> string

Examples๐Ÿ”—

caseArchivedAt(inputs)

caseArchivedAt(inputs)

Output: "2024-06-20T17:57:46.700164Z"

caseAssetEvidence๐Ÿ”—

Parses a case record and returns the list of asset evidence objects.

Input and output๐Ÿ”—

caseAssetEvidence(map) -> list

Examples๐Ÿ”—

caseAssetEvidence(inputs)

caseAssetEvidence(inputs)

Output: [, ...]

caseAssigneeId๐Ÿ”—

Parses a case record and returns the ID of the assignee.

Input and output๐Ÿ”—

caseAssigneeId(map) -> string

Examples๐Ÿ”—

caseAssigneeId(inputs)

caseAssigneeId(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

caseChangeAfter๐Ÿ”—

Returns an optional containing the after value for a field from delta.changes. Use .orValue() to provide a default or .hasValue() to check presence.

Input and output๐Ÿ”—

caseChangeAfter(map, string) -> optional

Examples๐Ÿ”—

caseChangeAfter(inputs, 'severity').orValue(0)

caseChangeAfter(inputs, 'severity').orValue(0)

Output: 6

caseChangeAfter(inputs, 'severity').hasValue()

caseChangeAfter(inputs, 'severity').hasValue()

Output: true

caseChangeAfter(inputs, 'nonexistent').orValue(0)

caseChangeAfter(inputs, 'nonexistent').orValue(0)

Output: 0

caseChangeAfter(inputs, 'nonexistent').hasValue()

caseChangeAfter(inputs, 'nonexistent').hasValue()

Output: false

caseChangeBefore๐Ÿ”—

Returns an optional containing the before value for a field from delta.changes. Use .orValue() to provide a default or .hasValue() to check presence.

Input and output๐Ÿ”—

caseChangeBefore(map, string) -> optional

Examples๐Ÿ”—

caseChangeBefore(inputs, 'severity').orValue(0)

caseChangeBefore(inputs, 'severity').orValue(0)

Output: 4

caseChangeBefore(inputs, 'severity').hasValue()

caseChangeBefore(inputs, 'severity').hasValue()

Output: true

caseChangeBefore(inputs, 'nonexistent').orValue(0)

caseChangeBefore(inputs, 'nonexistent').orValue(0)

Output: 0

caseChangeBefore(inputs, 'nonexistent').hasValue()

caseChangeBefore(inputs, 'nonexistent').hasValue()

Output: false

caseChanges๐Ÿ”—

Returns the delta.changes map from a case record. Each key is a field name, and each value is a map with before and after entries.

Input and output๐Ÿ”—

caseChanges(map) -> map

Examples๐Ÿ”—

caseChanges(inputs)

caseChanges(inputs)

Output: {"severity": {"before": 4, "after": 6}, "title": {"before": "Original Case Title", "after": "Updated Case Title"}}

caseCloseReason๐Ÿ”—

Parses a case record and returns the reason it was closed.

Input and output๐Ÿ”—

caseCloseReason(map) -> string

Examples๐Ÿ”—

caseCloseReason(inputs)

caseCloseReason(inputs)

Output: "reason for closing"

caseClosedAt๐Ÿ”—

Parses a case record and returns the date and time it was closed (RFC3339), or an empty string when unset.

Input and output๐Ÿ”—

caseClosedAt(map) -> string

Examples๐Ÿ”—

caseClosedAt(inputs)

caseClosedAt(inputs)

Output: "2026-03-09T11:57:04.205591Z"

caseComment๐Ÿ”—

Parses a case record and returns the comment associated with it.

Input and output๐Ÿ”—

caseComment(map) -> string

Examples๐Ÿ”—

caseComment(inputs)

caseComment(inputs)

Output: "This is a sample comment for the case."

caseCommentAuthorId๐Ÿ”—

Parses a case record and returns the ID of the author of the comment.

Input and output๐Ÿ”—

caseCommentAuthorId(map) -> string

Examples๐Ÿ”—

caseCommentAuthorId(inputs)

caseCommentAuthorId(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

caseCommentCreatedAt๐Ÿ”—

Parses a case record and returns the date and time the comment was created.

Input and output๐Ÿ”—

caseCommentCreatedAt(map) -> string

Examples๐Ÿ”—

caseCommentCreatedAt(inputs)

caseCommentCreatedAt(inputs)

Output: "2024-06-20T17:57:46.700164Z"

caseCommentMentions๐Ÿ”—

Parses a case record and returns a list of mentions in the comment.

Input and output๐Ÿ”—

caseCommentMentions(map) -> list

Examples๐Ÿ”—

caseCommentMentions(inputs)

caseCommentMentions(inputs)

Output: ["@secureworks", "@dac1ed31-111-4809-9cc9-9f99b6e"]

caseCommentOperation๐Ÿ”—

Parses a case record and returns the operation type of the comment.

Input and output๐Ÿ”—

caseCommentOperation(map) -> string

Examples๐Ÿ”—

caseCommentOperation(inputs)

caseCommentOperation(inputs)

Output: "create"

caseContributorIds๐Ÿ”—

Parses a case record and returns a list of contributor IDs.

Input and output๐Ÿ”—

caseContributorIds(map) -> list

Examples๐Ÿ”—

caseContributorIds(inputs)

caseContributorIds(inputs)

Output: ["dac1ed31-111-4809-9cc9-9f99b6e", "ff0197b0@clients"]

caseCreatedAt๐Ÿ”—

Parses a case record and returns the date and time it was created.

Input and output๐Ÿ”—

caseCreatedAt(map) -> string

Examples๐Ÿ”—

caseCreatedAt(inputs)

caseCreatedAt(inputs)

Output: "2024-06-20T17:57:45.592464Z"

caseCreatedById๐Ÿ”—

Parses a case record and returns the ID of the user that created it.

Input and output๐Ÿ”—

caseCreatedById(map) -> string

Examples๐Ÿ”—

caseCreatedById(inputs)

caseCreatedById(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

caseCreatedByPartner๐Ÿ”—

Parses a case record and returns true if it was created by a parent of the tenant.

Input and output๐Ÿ”—

caseCreatedByPartner(map) -> bool

Examples๐Ÿ”—

caseCreatedByPartner(inputs)

caseCreatedByPartner(inputs)

Output: false

caseDetectionEvidence๐Ÿ”—

Parses a case record and returns the list of detection evidence objects.

Input and output๐Ÿ”—

caseDetectionEvidence(map) -> list

Examples๐Ÿ”—

caseDetectionEvidence(inputs)

caseDetectionEvidence(inputs)

Output: [{id, isGenesis}, ...]

caseEventEvidence๐Ÿ”—

Parses a case record and returns the list of event evidence objects.

Input and output๐Ÿ”—

caseEventEvidence(map) -> list

Examples๐Ÿ”—

caseEventEvidence(inputs)

caseEventEvidence(inputs)

Output: [, ...]

caseFieldChanged๐Ÿ”—

Parses a case record and returns true if the provided field was modified.

Input and output๐Ÿ”—

caseFieldChanged(map, string) -> bool

Examples๐Ÿ”—

caseFieldChanged(inputs, 'priority')

caseFieldChanged(inputs, 'priority')

Output: true

caseFieldChanged(inputs, 'nonexistent_field')

caseFieldChanged(inputs, 'nonexistent_field')

Output: false

caseFileId๐Ÿ”—

Parses a case record and returns the file ID from delta.file (File Added events).

Input and output๐Ÿ”—

caseFileId(map) -> string

Examples๐Ÿ”—

caseFileId(inputs)

caseFileId(inputs)

Output: "f1e2d3c4-b5a6-7890-1234-567890abcdef"

caseFileName๐Ÿ”—

Parses a case record and returns the file name from delta.file (File Added events).

Input and output๐Ÿ”—

caseFileName(map) -> string

Examples๐Ÿ”—

caseFileName(inputs)

caseFileName(inputs)

Output: "evidence.pdf"

caseFileSize๐Ÿ”—

Parses a case record and returns the file size from delta.file (File Added events).

Input and output๐Ÿ”—

caseFileSize(map) -> int

Examples๐Ÿ”—

caseFileSize(inputs)

caseFileSize(inputs)

Output: 102400

caseFileStatus๐Ÿ”—

Parses a case record and returns the file lifecycle status from delta.file (File Added/Deleted events).

Input and output๐Ÿ”—

caseFileStatus(map) -> string

Examples๐Ÿ”—

caseFileStatus(inputs)

caseFileStatus(inputs)

Output: "SCHEDULED"

caseFileUploadedById๐Ÿ”—

Parses a case record and returns the user ID that uploaded the file from delta.file (File Added/Deleted events).

Input and output๐Ÿ”—

caseFileUploadedById(map) -> string

Examples๐Ÿ”—

caseFileUploadedById(inputs)

caseFileUploadedById(inputs)

Output: "auth0user123"

caseId๐Ÿ”—

Parses a case record and returns the ID.

Input and output๐Ÿ”—

caseId(map) -> string

Examples๐Ÿ”—

caseId(inputs)

caseId(inputs)

Output: "a251201f-9a26-4cd5-81f6-20509999933d"

caseIncidentAdvisorId๐Ÿ”—

Parses a case record and returns the incident advisor ID.

Input and output๐Ÿ”—

caseIncidentAdvisorId(map) -> string

Examples๐Ÿ”—

caseIncidentAdvisorId(inputs)

caseIncidentAdvisorId(inputs)

Output: "adv-123"

caseKeyFindings๐Ÿ”—

Parses a case record and returns the key findings content.

With an optional second argument, returns a specific field from the keyFindings object (for example, documentType or documentVersion).

Input and output๐Ÿ”—

caseKeyFindings(map) -> string
caseKeyFindings(map, string) -> string

Examples๐Ÿ”—

caseKeyFindings(inputs)

caseKeyFindings(inputs)

Output: "Sample Case Key Findings"

caseKeyFindings(inputs, 'documentType')

caseKeyFindings(inputs, 'documentType')

Output: "DOCUMENT_TYPE_MARKDOWN"

caseKeyFindings(inputs, 'documentVersion')

caseKeyFindings(inputs, 'documentVersion')

Output: "1"

caseLinkCreatedAt๐Ÿ”—

Returns the link creation timestamp from a case-change event (delta.link) or a bare link record.

Input and output๐Ÿ”—

caseLinkCreatedAt(map) -> string

Examples๐Ÿ”—

caseLinkCreatedAt(inputs)

caseLinkCreatedAt(inputs)

Output: "2026-04-30T18:53:00.483028Z"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))

Output: ["2026-04-30T18:53:00.483028Z"]

caseLinkIsInternal๐Ÿ”—

Returns whether the link is internal from a case-change event (delta.link) or a bare link record.

Input and output๐Ÿ”—

caseLinkIsInternal(map) -> bool

Examples๐Ÿ”—

caseLinkIsInternal(inputs)

caseLinkIsInternal(inputs)

Output: false

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))

Output: [false]

caseLinkReference๐Ÿ”—

Returns the link reference from a case-change event (delta.link) or a bare link record.

Input and output๐Ÿ”—

caseLinkReference(map) -> string

Examples๐Ÿ”—

caseLinkReference(inputs)

caseLinkReference(inputs)

Output: "EXT-12345"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))

Output: ["EXT-12345"]

caseLinkTitle๐Ÿ”—

Returns the link title from a case-change event (delta.link) or a bare link record.

Input and output๐Ÿ”—

caseLinkTitle(map) -> string

Examples๐Ÿ”—

caseLinkTitle(inputs)

caseLinkTitle(inputs)

Output: "External Ticket"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))

Output: ["External Ticket"]

caseLinkType๐Ÿ”—

Returns the link type from a case-change event (delta.link) or a bare link record.

Input and output๐Ÿ”—

caseLinkType(map) -> string

Examples๐Ÿ”—

caseLinkType(inputs)

caseLinkType(inputs)

Output: "External"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External')

caseLinks(inputs).filter(l, caseLinkType(l) == 'External')

Output: []

caseLinkUrl๐Ÿ”—

Returns the link URL from a case-change event (delta.link) or a bare link record.

Input and output๐Ÿ”—

caseLinkUrl(map) -> string

Examples๐Ÿ”—

caseLinkUrl(inputs)

caseLinkUrl(inputs)

Output: "https://example.com/tickets/EXT-12345"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))

Output: ["https://example.com/tickets/EXT-12345"]

Parses a case record and returns the full list of link objects.

Input and output๐Ÿ”—

caseLinks(map) -> list

Examples๐Ÿ”—

caseLinks(inputs)

caseLinks(inputs)

Output: [, ]

caseLinksReference๐Ÿ”—

Parses a case record and returns the list of reference strings from all links.

Input and output๐Ÿ”—

caseLinksReference(map) -> list

Examples๐Ÿ”—

caseLinksReference(inputs)

caseLinksReference(inputs)

Output: ["EXT-12345", "JIRA-456"]

caseLinksTitle๐Ÿ”—

Parses a case record and returns the list of title strings from all links.

Input and output๐Ÿ”—

caseLinksTitle(map) -> list

Examples๐Ÿ”—

caseLinksTitle(inputs)

caseLinksTitle(inputs)

Output: ["External Ticket", "Jira Ticket"]

caseLinksType๐Ÿ”—

Parses a case record and returns the list of type strings from all links (for example, External or Jira).

Input and output๐Ÿ”—

caseLinksType(map) -> list

Examples๐Ÿ”—

caseLinksType(inputs)

caseLinksType(inputs)

Output: ["External", "Jira"]

caseLinksUrl๐Ÿ”—

Parses a case record and returns the list of URL strings from all links.

Input and output๐Ÿ”—

caseLinksUrl(map) -> list

Examples๐Ÿ”—

caseLinksUrl(inputs)

caseLinksUrl(inputs)

Output: ["https://example.com/tickets/EXT-12345", "https://jira.example.com/..."]

caseManagedBy๐Ÿ”—

Parses a case record and returns the managed-by value (PROVIDER, CUSTOMER, UNKNOWN).

Input and output๐Ÿ”—

caseManagedBy(map) -> string

Examples๐Ÿ”—

caseManagedBy(inputs)

caseManagedBy(inputs)

Output: "CUSTOMER"

casePrimaryStatusId๐Ÿ”—

Parses a case record and returns the primary status ID.

Input and output๐Ÿ”—

casePrimaryStatusId(map) -> string

Examples๐Ÿ”—

casePrimaryStatusId(inputs)

casePrimaryStatusId(inputs)

Output: "8dafe9bc-cbf6-4b27-aff4-8959682f859c"

casePrimaryStatusName๐Ÿ”—

Parses a case record and returns the primary status name.

Input and output๐Ÿ”—

casePrimaryStatusName(map) -> string

Examples๐Ÿ”—

casePrimaryStatusName(inputs)

casePrimaryStatusName(inputs)

Output: "draft"

casePrimaryStatusTitle๐Ÿ”—

Parses a case record and returns the primary status title.

Input and output๐Ÿ”—

casePrimaryStatusTitle(map) -> string

Examples๐Ÿ”—

casePrimaryStatusTitle(inputs)

casePrimaryStatusTitle(inputs)

Output: "Draft"

casePrimaryVerdictId๐Ÿ”—

Parses a case record and returns the primary verdict ID.

Input and output๐Ÿ”—

casePrimaryVerdictId(map) -> string

Examples๐Ÿ”—

casePrimaryVerdictId(inputs)

casePrimaryVerdictId(inputs)

Output: "pv-1"

casePrimaryVerdictName๐Ÿ”—

Parses a case record and returns the primary verdict name.

Input and output๐Ÿ”—

casePrimaryVerdictName(map) -> string

Examples๐Ÿ”—

casePrimaryVerdictName(inputs)

casePrimaryVerdictName(inputs)

Output: "confirmed"

casePrimaryVerdictTitle๐Ÿ”—

Parses a case record and returns the primary verdict title.

Input and output๐Ÿ”—

casePrimaryVerdictTitle(map) -> string

Examples๐Ÿ”—

casePrimaryVerdictTitle(inputs)

casePrimaryVerdictTitle(inputs)

Output: "Confirmed"

casePriority๐Ÿ”—

Parses a case record and returns the priority of the case as a word (Low, Medium, High, Critical).

An optional second argument of true returns the priority as an integer (1-4).

Input and output๐Ÿ”—

casePriority(map) -> string
casePriority(map, bool) -> int

Examples๐Ÿ”—

casePriority(inputs)

casePriority(inputs)

Output: "High"

casePriority(inputs, true)

casePriority(inputs, true)

Output: 3

caseProcessingStatus๐Ÿ”—

Parses a case record and returns the processing status map.

Input and output๐Ÿ”—

caseProcessingStatus(map) -> map

Examples๐Ÿ”—

caseProcessingStatus(inputs)

caseProcessingStatus(inputs)

Output: {"alerts": "SUCCESS", "assets": "SUCCESS", "events": "SUCCESS"}

caseRiskScore๐Ÿ”—

Parses a case record and returns the risk score.

Input and output๐Ÿ”—

caseRiskScore(map) -> double

Examples๐Ÿ”—

caseRiskScore(inputs)

caseRiskScore(inputs)

Output: 7.2

caseRuleId๐Ÿ”—

Parses a case record and returns the auto case rule ID that created it.

Input and output๐Ÿ”—

caseRuleId(map) -> string

Examples๐Ÿ”—

caseRuleId(inputs)

caseRuleId(inputs)

Output: "12345"

caseSearchEvidence๐Ÿ”—

Parses a case record and returns the list of search evidence objects.

Input and output๐Ÿ”—

caseSearchEvidence(map) -> list

Examples๐Ÿ”—

caseSearchEvidence(inputs)

caseSearchEvidence(inputs)

Output: [, ...]

caseSecondaryStatusId๐Ÿ”—

Parses a case record and returns the secondary status ID.

Input and output๐Ÿ”—

caseSecondaryStatusId(map) -> string

Examples๐Ÿ”—

caseSecondaryStatusId(inputs)

caseSecondaryStatusId(inputs)

Output: "ss-1"

caseSecondaryStatusName๐Ÿ”—

Parses a case record and returns the secondary status name.

Input and output๐Ÿ”—

caseSecondaryStatusName(map) -> string

Examples๐Ÿ”—

caseSecondaryStatusName(inputs)

caseSecondaryStatusName(inputs)

Output: "under_review"

caseSecondaryStatusReason๐Ÿ”—

Parses a case record and returns the list of secondary status reasons.

Input and output๐Ÿ”—

caseSecondaryStatusReason(map) -> list

Examples๐Ÿ”—

caseSecondaryStatusReason(inputs)

caseSecondaryStatusReason(inputs)

Output: ["reason1", "reason2"]

caseSecondaryStatusTitle๐Ÿ”—

Parses a case record and returns the secondary status title.

Input and output๐Ÿ”—

caseSecondaryStatusTitle(map) -> string

Examples๐Ÿ”—

caseSecondaryStatusTitle(inputs)

caseSecondaryStatusTitle(inputs)

Output: "Under Review"

caseSecondaryVerdictId๐Ÿ”—

Parses a case record and returns the secondary verdict ID.

Input and output๐Ÿ”—

caseSecondaryVerdictId(map) -> string

Examples๐Ÿ”—

caseSecondaryVerdictId(inputs)

caseSecondaryVerdictId(inputs)

Output: "sv-1"

caseSecondaryVerdictName๐Ÿ”—

Parses a case record and returns the secondary verdict name.

Input and output๐Ÿ”—

caseSecondaryVerdictName(map) -> string

Examples๐Ÿ”—

caseSecondaryVerdictName(inputs)

caseSecondaryVerdictName(inputs)

Output: "malicious"

caseSecondaryVerdictTitle๐Ÿ”—

Parses a case record and returns the secondary verdict title.

Input and output๐Ÿ”—

caseSecondaryVerdictTitle(map) -> string

Examples๐Ÿ”—

caseSecondaryVerdictTitle(inputs)

caseSecondaryVerdictTitle(inputs)

Output: "Malicious"

caseSeverity๐Ÿ”—

Parses a case record and returns the severity as a word (Informational, Low, Medium, High, Critical).

For inputs.case, uses severity values 2, 4, 6, 8, and 10. For V1/V2 records, uses priority values 1-4.

An optional second argument of false returns the raw numeric value.

Input and output๐Ÿ”—

caseSeverity(map) -> string
caseSeverity(map, bool) -> int

Examples๐Ÿ”—

caseSeverity(inputs)

caseSeverity(inputs)

Output: "Medium"

caseSeverity(inputs, false)

caseSeverity(inputs, false)

Output: 6

caseShortId๐Ÿ”—

Parses a case record and returns the short ID.

Input and output๐Ÿ”—

caseShortId(map) -> string

Examples๐Ÿ”—

caseShortId(inputs)

caseShortId(inputs)

Output: "INV41773"

caseSourceId๐Ÿ”—

Parses a case record and returns the source ID.

Input and output๐Ÿ”—

caseSourceId(map) -> string

Examples๐Ÿ”—

caseSourceId(inputs)

caseSourceId(inputs)

Output: "src-auto-001"

caseSourceName๐Ÿ”—

Parses a case record and returns the source name.

Input and output๐Ÿ”—

caseSourceName(map) -> string

Examples๐Ÿ”—

caseSourceName(inputs)

caseSourceName(inputs)

Output: "auto_case_rule"

caseSourceTitle๐Ÿ”—

Parses a case record and returns the source display title.

Input and output๐Ÿ”—

caseSourceTitle(map) -> string

Examples๐Ÿ”—

caseSourceTitle(inputs)

caseSourceTitle(inputs)

Output: "Auto-Generated"

caseStatus๐Ÿ”—

Parses a case record and returns the status.

Input and output๐Ÿ”—

caseStatus(map) -> string
caseStatus(map, string) -> string

Examples๐Ÿ”—

caseStatus(inputs)

caseStatus(inputs)

Output: "OPEN"

caseStatus(inputs, 'v1')

caseStatus(inputs, 'v1')

Output: "Open"

caseTags๐Ÿ”—

Parses a case record and returns the list of tags.

Input and output๐Ÿ”—

caseTags(map) -> list

Examples๐Ÿ”—

caseTags(inputs)

caseTags(inputs)

Output: ["automation", "playbook"]

caseTenantId๐Ÿ”—

Parses a case record and returns the ID of the tenant.

Input and output๐Ÿ”—

caseTenantId(map) -> string

Examples๐Ÿ”—

caseTenantId(inputs)

caseTenantId(inputs)

Output: "12345"

caseThirdPartyId๐Ÿ”—

Parses a case record and returns the ID of a third-party record associated with it.

Input and output๐Ÿ”—

caseThirdPartyId(map) -> string

Examples๐Ÿ”—

caseThirdPartyId(inputs)

caseThirdPartyId(inputs)

Output: "bdf9f35a8383121055c9e330ceaad3b8"

caseThirdPartyType๐Ÿ”—

Parses a case record and returns the type of a third-party record associated with it.

Input and output๐Ÿ”—

caseThirdPartyType(map) -> string

Examples๐Ÿ”—

caseThirdPartyType(inputs)

caseThirdPartyType(inputs)

Output: "SNOW"

caseTitle๐Ÿ”—

Parses a case record and returns the title.

Input and output๐Ÿ”—

caseTitle(map) -> string

Examples๐Ÿ”—

caseTitle(inputs)

caseTitle(inputs)

Output: "Taegis Watchlist Case"

caseType๐Ÿ”—

Parses a case record and returns the type.

An optional second argument of 'v1' or 'v2' converts the type. The default is 'v2'.

Input and output๐Ÿ”—

caseType(map) -> string
caseType(map, string) -> string

Examples๐Ÿ”—

caseType(inputs)

caseType(inputs)

Output: "SECURITY_INVESTIGATION"

caseType(inputs, 'v1')

caseType(inputs, 'v1')

Output: "Security Investigation"

caseTypeId๐Ÿ”—

Parses a case record and returns the raw type ID from the structured type object.

Returns an empty string when the type is absent or not an object.

Input and output๐Ÿ”—

caseTypeId(map) -> string

Examples๐Ÿ”—

caseTypeId(inputs)

caseTypeId(inputs)

Output: "00000006-0000-4000-a000-000000000001"

caseTypeTitle๐Ÿ”—

Parses a case record and returns the type display title from the structured type object.

Returns an empty string when the type is absent or not an object.

Input and output๐Ÿ”—

caseTypeTitle(map) -> string

Examples๐Ÿ”—

caseTypeTitle(inputs)

caseTypeTitle(inputs)

Output: "Investigation"

caseUpdatedAt๐Ÿ”—

Parses a case record and returns the date and time of the last update.

Input and output๐Ÿ”—

caseUpdatedAt(map) -> string

Examples๐Ÿ”—

caseUpdatedAt(inputs)

caseUpdatedAt(inputs)

Output: "2024-06-20T17:57:46.700164Z"

caseUpdatedById๐Ÿ”—

Parses a case record and returns the ID of the user that last updated it.

Input and output๐Ÿ”—

caseUpdatedById(map) -> string

Examples๐Ÿ”—

caseUpdatedById(inputs)

caseUpdatedById(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

cel.bind๐Ÿ”—

Creates a local variable binding within an expression to avoid recomputing expensive operations.

Input and output๐Ÿ”—

cel.bind(var_name, value, expression) -> any

Creates a local variable that can be referenced within the expression.

The variable is only available in the scope of the third argument (expression).

This is useful for:

  • Avoiding repeated computation of expensive operations.
  • Making complex expressions more readable.
  • Creating intermediate values for cleaner logic.

The variable name is provided as an identifier (not a string).

The value can be any CEL expression.

The expression is evaluated with the variable in scope.

Use cases๐Ÿ”—

Avoid repeated computation.

cel.bind(name, inputs.user.name.uppercase(), name + ' - ' + string(name.size()))

Avoid repeating expensive operations and improve readability.

Simplify complex conditions.

cel.bind(withTax, inputs.price * 1.2, withTax > 100 ? withTax * 0.9 : withTax)

Calculate an intermediate value and reuse it.

Chain multiple bindings.

cel.bind(x, 5, cel.bind(y, x * 2, cel.bind(z, y + 3, x + y + z)))

Output: 26

Create nested variable bindings.

Work with lists.

cel.bind(nums, [1, 2, 3, 4, 5], cel.bind(doubled, nums.map(n, n * 2), doubled.filter(n, n > 5)))

Output: [6, 8, 10]

Double all values, then filter the result.

Complex object access.

cel.bind(user, inputs.users[0], user.name + ' (' + user.email + ')')

Access an object once and reuse it multiple times.

Examples๐Ÿ”—

cel.bind(x, 10, x * x)

cel.bind(x, 10, x * x)

Output: 100

cel.bind(user, 'John', 'Hello ' + user)

cel.bind(user, 'John', 'Hello ' + user)

Output: "Hello John"

cel.bind(list, [1,2,3], list.size() + list[0])

cel.bind(list, [1,2,3], list.size() + list[0])

Output: 4

charAt๐Ÿ”—

Returns the character at the specified index in the string.

Input and output๐Ÿ”—

string.charAt(int) -> string

Returns the character (as a single-character string) at the specified zero-based index.

Returns an empty string if the index is out of bounds.

Examples๐Ÿ”—

'hello'.charAt(0)

'hello'.charAt(0)

Output: "h"

'hello'.charAt(4)

'hello'.charAt(4)

Output: "o"

collect๐Ÿ”—

Returns a list of map values that match the provided path argument.

Input and output๐Ÿ”—

collect(list, string) -> list

Examples๐Ÿ”—

[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')

[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')

Output: ["value1", "value3"]

contains๐Ÿ”—

Returns true if any element in the string or list matches the provided string or list (case-sensitive).

An optional second argument of true causes the match to ignore case.

Input and output๐Ÿ”—

contains(string, string) -> bool
contains(string, string, bool) -> bool
contains(string, list) -> bool
contains(string, list, bool) -> bool
contains(list, string) -> bool
contains(list, string, bool) -> bool
contains(list, list) -> bool
contains(list, list, bool) -> bool

Examples๐Ÿ”—

"apple".contains("app")

"apple".contains("app")

Output: true

"apple".contains("APP", true)

"apple".contains("APP", true)

Output: true

"apple".contains(["app"])

"apple".contains(["app"])

Output: true

"apple".contains(["APP"], true)

"apple".contains(["APP"], true)

Output: true

["apple", "banana"].contains("app")

["apple", "banana"].contains("app")

Output: true

["apple", "banana"].contains("APP", true)

["apple", "banana"].contains("APP", true)

Output: true

["apple", "banana"].contains(["app"])

["apple", "banana"].contains(["app"])

Output: true

["apple", "banana"].contains(["APP"], true)

["apple", "banana"].contains(["APP"], true)

Output: true

count๐Ÿ”—

Returns a count of the list elements that match the provided string argument, or the keys in a map that match it.

Input and output๐Ÿ”—

count(list, string) -> int

Examples๐Ÿ”—

count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")

count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")

Output: 2

Returns a Taegis Sharelink for an alert, investigation, or asset.

Input and output๐Ÿ”—

createShareLink(map) -> string

Examples๐Ÿ”—

createShareLink(inputs)

createShareLink(inputs)

Output: "https://ctpx.secureworks.com/share/14f-ca9d-ad47-34db-2243b945ce2112f"

decodeBase64๐Ÿ”—

Returns a decoded base64 input string.

Input and output๐Ÿ”—

decodeBase64(string) -> string

Examples๐Ÿ”—

decodeBase64("aGVsbG8gd29ybGQ=")

decodeBase64("aGVsbG8gd29ybGQ=")

Output: "hello world"

decodeJSON๐Ÿ”—

Returns a JSON object after decoding the input string.

Input and output๐Ÿ”—

decodeJSON(string) -> any

Examples๐Ÿ”—

decodeJSON('{"key": "value"}')

decodeJSON('{"key": "value"}')

Output: {"key":"value"}

decodeYAML๐Ÿ”—

Decodes YAML input to any data type.

Input and output๐Ÿ”—

decodeYAML(string) -> any

Examples๐Ÿ”—

decodeYAML("key: value")

decodeYAML("key: value")

Output: {"key":"value"}

detectionAttackTechniqueIds๐Ÿ”—

Parses a detection record and returns the attack technique IDs value.

Input and output๐Ÿ”—

detectionAttackTechniqueIds(map) -> list

Examples๐Ÿ”—

detectionAttackTechniqueIds(inputs)

detectionAttackTechniqueIds(inputs)

Output: ["T1096", "T1214"]

detectionConfidence๐Ÿ”—

Parses a detection record and returns the confidence value.

Input and output๐Ÿ”—

detectionConfidence(map) -> double

Examples๐Ÿ”—

detectionConfidence(inputs)

detectionConfidence(inputs)

Output: 0.5

detectionCreatedAtNanos๐Ÿ”—

Parses a detection record and returns the nanoseconds value of the time the detection was created.

Input and output๐Ÿ”—

detectionCreatedAtNanos(map) -> int

Examples๐Ÿ”—

detectionCreatedAtNanos(inputs)

detectionCreatedAtNanos(inputs)

Output: 796357058

detectionCreatedAtSeconds๐Ÿ”—

Parses a detection record and returns the created_at value as a measure of seconds from epoch.

Input and output๐Ÿ”—

detectionCreatedAtSeconds(map) -> int

Examples๐Ÿ”—

detectionCreatedAtSeconds(inputs)

detectionCreatedAtSeconds(inputs)

Output: 1636029855

detectionDescription๐Ÿ”—

Parses a detection record and returns the description value.

Input and output๐Ÿ”—

detectionDescription(map) -> string

Examples๐Ÿ”—

detectionDescription(inputs)

detectionDescription(inputs)

Output: "This is a sample Taegis Watchlist Detection"

detectionDestinationIPs๐Ÿ”—

Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled destinationIPAddress (case insensitive).

Input and output๐Ÿ”—

detectionDestinationIPs(map) -> list

Examples๐Ÿ”—

detectionDestinationIPs(inputs)

detectionDestinationIPs(inputs)

Output: ["192.168.0.1", "192.168.0.2"]

detectionDetectorId๐Ÿ”—

Parses a detection record and returns the detector ID value.

Input and output๐Ÿ”—

detectionDetectorId(map) -> string

Examples๐Ÿ”—

detectionDetectorId(inputs)

detectionDetectorId(inputs)

Output: "app:event-filter"

detectionDetectorName๐Ÿ”—

Parses a detection record and returns the detector name value.

Input and output๐Ÿ”—

detectionDetectorName(map) -> string

Examples๐Ÿ”—

detectionDetectorName(inputs)

detectionDetectorName(inputs)

Output: "Taegis Watchlist"

detectionDomains๐Ÿ”—

Parses a detection record and returns a unique list of domain name values from the detection entities field where the entity is labeled ipdomain, topprivateipdomain, domainname, authdomainname, sourceauthdomainname, or targetauthdomainname (case insensitive).

Input and output๐Ÿ”—

detectionDomains(map) -> list

Examples๐Ÿ”—

detectionDomains(inputs)

detectionDomains(inputs)

Output: ["example.com", "a.example.com"]

detectionEnrichment๐Ÿ”—

Parses a detection record and the enrichment data and returns the first value matching the path provided.

Input and output๐Ÿ”—

detectionEnrichment(map, string) -> any

Examples๐Ÿ”—

detectionEnrichment(inputs, 'rare_program_rare_ip.programs')

detectionEnrichment(inputs, 'rare_program_rare_ip.programs')

Output: ["foo.exe", "bar.exe"]

detectionEnrichment(inputs, 'doesnotexist')

detectionEnrichment(inputs, 'doesnotexist')

Output: []

detectionEntities๐Ÿ”—

Parses a detection record and returns the entities value.

Input and output๐Ÿ”—

detectionEntities(map) -> list

Examples๐Ÿ”—

detectionEntities(inputs)

detectionEntities(inputs)

Output: ["hostname:abc", "sensorId:12345", "fileName:c:\windows\syswow64\cmd.exe"]

detectionEntity๐Ÿ”—

Parses a detection record and returns the entity values that match the provided entity name (case insensitive).

Input and output๐Ÿ”—

detectionEntity(map, string) -> list

Examples๐Ÿ”—

detectionEntity(inputs, 'username')

detectionEntity(inputs, 'username')

Output: ["sample_user", "another_sample_user"]

detectionEventIds๐Ÿ”—

Parses a detection record and returns a list of event ID values.

Input and output๐Ÿ”—

detectionEventIds(map) -> list

Examples๐Ÿ”—

detectionEventIds(inputs)

detectionEventIds(inputs)

Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

detectionGroupKey๐Ÿ”—

Parses a detection record and returns the group_key value.

Input and output๐Ÿ”—

detectionGroupKey(map) -> string

Examples๐Ÿ”—

detectionGroupKey(inputs)

detectionGroupKey(inputs)

Output: "12345:app:event-filter:80c0809b-153f-4b81-bb7c-52fcb83c7127"

detectionHostnames๐Ÿ”—

Parses a detection record and returns a unique list of values from the detection entities field where the entity is labeled hostname, sourcehostname, desthostname, workstationname, or computername (case insensitive).

Input and output๐Ÿ”—

detectionHostnames(map) -> list

Examples๐Ÿ”—

detectionHostnames(inputs)

detectionHostnames(inputs)

Output: ["sample_hostname", "another_sample_hostname"]

detectionIPs๐Ÿ”—

Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled ipAddress (case insensitive).

Input and output๐Ÿ”—

detectionIPs(map) -> list

Examples๐Ÿ”—

detectionIPs(inputs)

detectionIPs(inputs)

Output: ["192.168.0.1", "192.168.0.2"]

detectionId๐Ÿ”—

Parses a detection record and returns the ID or UUID.

Input and output๐Ÿ”—

detectionId(map) -> string

Examples๐Ÿ”—

detectionId(inputs)

detectionId(inputs)

Output: "detection://priv:endpoint-redcloak:12345:1678899090095:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"

detectionInvestigationIds๐Ÿ”—

Parses a detection record and returns a list of investigation IDs associated with the detection.

Input and output๐Ÿ”—

detectionInvestigationIds(map) -> list

Examples๐Ÿ”—

detectionInvestigationIds(inputs)

detectionInvestigationIds(inputs)

Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

detectionMitreAttackInfo๐Ÿ”—

Parses a detection record and returns a list of mitre_attack_info values.

Input and output๐Ÿ”—

detectionMitreAttackInfo(map) -> list

Examples๐Ÿ”—

detectionMitreAttackInfo(inputs)

detectionMitreAttackInfo(inputs)

Output: [{"description":"Adversaries may attempt...","technique":"Process Discovery","technique_id":"T1057"}]

detectionObservationIds๐Ÿ”—

Parses a detection record and returns a list of observation ID values.

Input and output๐Ÿ”—

detectionObservationIds(map) -> list

Examples๐Ÿ”—

detectionObservationIds(inputs)

detectionObservationIds(inputs)

Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

detectionReferences๐Ÿ”—

Parses a detection record and returns a list of references associated with the detection.

Input and output๐Ÿ”—

detectionReferences(map) -> list

Examples๐Ÿ”—

detectionReferences(inputs)

detectionReferences(inputs)

Output: [{"description": "External Detection Ref", "url": "https://example.com/detection/29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"}]

detectionResolution๐Ÿ”—

Parses a detection record and returns the resolution value.

Input and output๐Ÿ”—

detectionResolution(map) -> string

Examples๐Ÿ”—

detectionResolution(inputs)

detectionResolution(inputs)

Output: "open"

detectionResolutionReason๐Ÿ”—

Parses a detection record and returns the resolution reason value.

Input and output๐Ÿ”—

detectionResolutionReason(map) -> string

Examples๐Ÿ”—

detectionResolutionReason(inputs)

detectionResolutionReason(inputs)

Output: "Valid activity for this user."

detectionRuleId๐Ÿ”—

Parses a detection record and returns the rule ID.

Input and output๐Ÿ”—

detectionRuleId(map) -> string

Examples๐Ÿ”—

detectionRuleId(inputs)

detectionRuleId(inputs)

Output* "267658fe-65f1-4145-8753-d45fbf9ed6d3"

detectionSensorIds๐Ÿ”—

Parses a detection record and returns a list of sensor ID values.

Input and output๐Ÿ”—

detectionSensorIds(map) -> list

Examples๐Ÿ”—

detectionSensorIds(inputs)

detectionSensorIds(inputs)

Output: ["12345", "1234-12345-123"]

detectionSensorTypes๐Ÿ”—

Parses a detection record and returns a list of unique sensor type values (in uppercase).

Input and output๐Ÿ”—

detectionSensorTypes(map) -> list

Examples๐Ÿ”—

detectionSensorTypes(inputs)

detectionSensorTypes(inputs)

Output: ["ENDPOINT_REDCLOAK", "ENDPOINT_TAEGIS"]

detectionSeverity๐Ÿ”—

Parses a detection record and returns the severity value.

Input and output๐Ÿ”—

detectionSeverity(map) -> double

Examples๐Ÿ”—

detectionSeverity(inputs)

detectionSeverity(inputs)

Output: 0.75

detectionSeverityNice๐Ÿ”—

Parses a detection record and returns the human-friendly severity value as a word (Informational, Low, Medium, High, Critical).

Input and output๐Ÿ”—

detectionSeverityNice(map) -> string

Examples๐Ÿ”—

detectionSeverityNice(inputs)

detectionSeverityNice(inputs)

Output: "High"

detectionSourceEntities๐Ÿ”—

Returns the list of source entities from a detection's source_entities field.

Input and output๐Ÿ”—

detectionSourceEntities(map) -> list

Examples๐Ÿ”—

detectionSourceEntities(inputs)

detectionSourceEntities(inputs)

Output: [{"id": "...", "display_name": "...", "perspective": "SOURCE", ...}]

detectionSourceEntityProperties๐Ÿ”—

Filters source_entities by property_type and returns values for the specified property keys.

Input and output๐Ÿ”—

detectionSourceEntityProperties(map, string, list) -> list

Examples๐Ÿ”—

detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])

detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])

Output: ["jdoe", "jdoe"]

detectionSourceIPs๐Ÿ”—

Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled sourceIPAddress (case insensitive).

Input and output๐Ÿ”—

detectionSourceIPs(map) -> list

Examples๐Ÿ”—

detectionSourceIPs(inputs)

detectionSourceIPs(inputs)

Output: ["192.168.0.1", "192.168.0.2"]

detectionStatus๐Ÿ”—

Parses a detection record and returns the status value.

Input and output๐Ÿ”—

detectionStatus(map) -> string

Examples๐Ÿ”—

detectionStatus(inputs)

detectionStatus(inputs)

Output: "open"

detectionTags๐Ÿ”—

Parses a detection record and returns a list of tags.

Input and output๐Ÿ”—

detectionTags(map) -> list

Examples๐Ÿ”—

detectionTags(inputs)

detectionTags(inputs)

Output: ["detectionRule:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "compactor:handler"]

detectionTargetEntities๐Ÿ”—

Returns the list of target entities from a detection's target_entities field.

Input and output๐Ÿ”—

detectionTargetEntities(map) -> list

Examples๐Ÿ”—

detectionTargetEntities(inputs)

detectionTargetEntities(inputs)

Output: [{"id": "...", "display_name": "...", "perspective": "TARGET", ...}]

detectionTargetEntityProperties๐Ÿ”—

Filters target_entities by property_type and returns values for the specified property keys.

Input and output๐Ÿ”—

detectionTargetEntityProperties(map, string, list) -> list

Examples๐Ÿ”—

detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])

detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])

Output: ["abc123def456"]

detectionTenantId๐Ÿ”—

Parses a detection record and returns the tenant ID.

Input and output๐Ÿ”—

detectionTenantId(map) -> string

Examples๐Ÿ”—

detectionTenantId(inputs)

detectionTenantId(inputs)

Output: "12345"

detectionThirdPartyDetail๐Ÿ”—

Parses a detection record and the third-party detail data and returns the first value matching the path provided.

Input and output๐Ÿ”—

detectionThirdPartyDetail(map, string) -> list

Examples๐Ÿ”—

detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')

detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')

Output: ["F86DBD0D-6571-44A0-BAE1-43B83CF430AD"]

detectionTitle๐Ÿ”—

Parses a detection record and returns the title value.

Input and output๐Ÿ”—

detectionTitle(map) -> string

Examples๐Ÿ”—

detectionTitle(inputs)

detectionTitle(inputs)

Output: "Taegis Watchlist Detection"

detectionUpdatedAtNanos๐Ÿ”—

Parses a detection record and returns the nanoseconds value of the time the detection was modified.

Input and output๐Ÿ”—

detectionUpdatedAtNanos(map) -> int

Examples๐Ÿ”—

detectionUpdatedAtNanos(inputs)

detectionUpdatedAtNanos(inputs)

Output: 796357058

detectionUpdatedAtSeconds๐Ÿ”—

Parses a detection record and returns the updated_at value as a measure of seconds from epoch.

Input and output๐Ÿ”—

detectionUpdatedAtSeconds(map) -> int

Examples๐Ÿ”—

detectionUpdatedAtSeconds(inputs)

detectionUpdatedAtSeconds(inputs)

Output: 1697207995554

detectionUsernames๐Ÿ”—

Parses a detection record and returns a unique list of lowercase username values from the detection entities field where the entity is labeled username (case insensitive).

Input and output๐Ÿ”—

detectionUsernames(map) -> list

Examples๐Ÿ”—

detectionUsernames(inputs)

detectionUsernames(inputs)

Output: ["sample_user", "another_sample_user"]

distinct๐Ÿ”—

Removes duplicate elements from a list, preserving the first occurrence of each element.

Input and output๐Ÿ”—

list.distinct() -> list

Returns a new list containing only unique elements from the original list.

The first occurrence of each element is preserved in the order encountered.

Duplicates are removed.

Use cases๐Ÿ”—

Remove duplicates from user input.

user_tags.distinct()

Clean up duplicate tags.

Get unique values.

results.map(r, r.category).distinct()

Get all unique categories from the results.

Deduplicate IDs.

id_list.distinct()

Ensure that there are no duplicate IDs.

Clean data.

inputs.values.distinct()

Remove duplicates.

Use set-like operations.

list1.distinct().size() == list1.size()

Check whether a list has no duplicates.

Combine with a filter.

items.filter(i, i.active).map(i, i.id).distinct()

Get the unique IDs of active items.

Preserve order.

[3, 1, 2, 1, 3].distinct()

Output: [3, 1, 2]

Preserve the order of the first occurrence of each element.

Notes๐Ÿ”—

  • Preserves the order of the first occurrence.
  • Works with any comparable type.
  • Empty lists remain empty.
  • Doesn't sort the output.

Examples๐Ÿ”—

[1, 2, 2, 3, 3, 3].distinct()

[1, 2, 2, 3, 3, 3].distinct()

Output: [1, 2, 3]

Remove duplicate numbers.

['b', 'b', 'c', 'a', 'c'].distinct()

['b', 'b', 'c', 'a', 'c'].distinct()

Output: ['b', 'c', 'a']

Remove duplicate strings and preserve their order.

[1, 2, 3].distinct()

[1, 2, 3].distinct()

Output: [1, 2, 3]

The list is already unique.

[1, 1, 1].distinct()

[1, 1, 1].distinct()

Output: [1]

Remove all duplicate elements.

[].distinct()

[].distinct()

Output: []

An empty list remains empty.

domains๐Ÿ”—

Returns true if the provided username argument is in one or more of the provided domains.

Input and output๐Ÿ”—

domains(map) -> list

Examples๐Ÿ”—

domains(inputs)

domains(inputs)

Output: ["example.com","foo.com"]

encodeBase64๐Ÿ”—

Returns an encoded string input as a base64 string.

Input and output๐Ÿ”—

encodeBase64(string) -> string

Examples๐Ÿ”—

encodeBase64("hello world")

encodeBase64("hello world")

Output: "aGVsbG8gd29ybGQ="

encodeJSON๐Ÿ”—

Returns an encoded string input as a JSON string.

Input and output๐Ÿ”—

encodeJSON(string) -> string

Examples๐Ÿ”—

encodeJSON({"key":"value"})

encodeJSON({"key":"value"})

Output: "{\"key\":\"value\"}"

encodeYAML๐Ÿ”—

Encodes any value as a YAML string.

Input and output๐Ÿ”—

encodeYAML(string) -> string

Examples๐Ÿ”—

encodeYAML({"key":"value"})

encodeYAML({"key":"value"})

Output: "key: value\n"

entityValue๐Ÿ”—

Parses an entity record and returns a list of values for the provided entity property.

Input and output๐Ÿ”—

entityValue(map, string) -> list

Examples๐Ÿ”—

entityValue(inputs, "username")

entityValue(inputs, "username")

Output: ["john"]

entityValue(inputs, "nonexistent")

entityValue(inputs, "nonexistent")

Output: []

entityValues๐Ÿ”—

Parses an entity record and returns a list of values associated with the entity.

Input and output๐Ÿ”—

entityValues(map) -> list

Examples๐Ÿ”—

entityValues(inputs)

entityValues(inputs)

Output: ["example.com", "john@example.com", "john"]

exists๐Ÿ”—

Iterates on a list or map and validates that a condition is true for at least one of the elements.

Input and output๐Ÿ”—

exists(list, predicate) -> bool
exists(map, predicate) -> bool

Examples๐Ÿ”—

[1, 2, 3].exists(i, i % 2 != 0)

[1, 2, 3].exists(i, i % 2 != 0)

Output: true

{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))

{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))

Output: false

exists_one๐Ÿ”—

Iterates on a list or map and validates that a condition is true for exactly one of the elements.

Input and output๐Ÿ”—

exists_one(list, predicate) -> bool
exists_one(map, predicate) -> bool

Examples๐Ÿ”—

[1, 2, 2].exists_one(i, i < 2)

[1, 2, 2].exists_one(i, i < 2)

Output: true

{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))

{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))

Output: false

filehashes๐Ÿ”—

Returns a list of file hashes from an alert or entity if found.

Input and output๐Ÿ”—

filehashes(map) -> list

Examples๐Ÿ”—

filehashes(inputs)

filehashes(inputs)

Output: ["445362b51bf855f62f9af7bb8362c8b27c7bc1ceb1dc88fd41a72de19b779969", "2e5a8590cf6848968fc23de3fa1e25f1", "9785001b0dcf755eddb8af294a373c0b87b2498660f724e76c4d53f9c217c7a3"]

filter๐Ÿ”—

Iterates on a list and returns the elements that match the provided criteria.

Input and output๐Ÿ”—

filter(list, predicate) -> list

Examples๐Ÿ”—

["a", "ab", "c"].filter(x, x.contains("a"))

["a", "ab", "c"].filter(x, x.contains("a"))

Output: ["a", "ab"]

["a", "ab", "c"].filter(x, x.contains("d"))

["a", "ab", "c"].filter(x, x.contains("d"))

Output: []

findingCheck๐Ÿ”—

Parses an identity finding record and returns the check map, or returns a specific entry when a second argument is provided.

Input and output๐Ÿ”—

findingCheck(map) -> map
findingCheck(map, string) -> any

Examples๐Ÿ”—

findingCheck(inputs)

findingCheck(inputs)

Output: {'autoResolutionDisabled':false,'category':'CONFIGURATION', ... }

findingCheck(inputs, "module")

findingCheck(inputs, "module")

Output: "IDENTITY"

findingCheck(inputs, "id")

findingCheck(inputs, "id")

Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"

findingCheck(inputs, "title")

findingCheck(inputs, "title")

Output: "Application shall not have unclaimed DNS names that are susceptible to takeover"

findingCheck(inputs, "description")

findingCheck(inputs, "description")

Output: "Threat actors can exploit vulnerabilities in Microsoft Entra ID applications by registering unclaimed subdomains, also known as dangling Fully Qualified Domain Names (FQDNs)."

findingCheck(inputs, "enabled")

findingCheck(inputs, "enabled")

Output: true

findingClosedAt๐Ÿ”—

Parses an identity finding record and returns the closed-at timestamp.

Input and output๐Ÿ”—

findingClosedAt(map) -> string

Examples๐Ÿ”—

findingClosedAt(inputs)

findingClosedAt(inputs)

Output: "2025-04-28T16:57:49.591956Z"

findingConfidenceScore๐Ÿ”—

Parses an identity finding record and returns the confidence score.

Input and output๐Ÿ”—

findingConfidenceScore(map) -> double

Examples๐Ÿ”—

findingConfidenceScore(inputs)

findingConfidenceScore(inputs)

Output: "1.0"

findingFieldChanged๐Ÿ”—

Parses a finding record and returns true if the provided field was modified.

Input and output๐Ÿ”—

findingFieldChanged(map, string) -> bool

Examples๐Ÿ”—

findingFieldChanged(inputs, 'status')

findingFieldChanged(inputs, 'status')

Output: true

findingFieldChanged(inputs, 'nonexistent_field')

findingFieldChanged(inputs, 'nonexistent_field')

Output: false

findingFirstSeen๐Ÿ”—

Parses an identity finding record and returns the first-seen timestamp.

Input and output๐Ÿ”—

findingFirstSeen(map) -> string

Examples๐Ÿ”—

findingFirstSeen(inputs)

findingFirstSeen(inputs)

Output: "2025-03-12T16:57:49.591956Z"

findingId๐Ÿ”—

Parses an identity finding record and returns the ID.

Input and output๐Ÿ”—

findingId(map) -> string

Examples๐Ÿ”—

findingId(inputs)

findingId(inputs)

Output: "f1234567-89ab-cdef-0123-456789abcdef"

findingIdentityCity๐Ÿ”—

Parses an identity finding record and returns the city from the identity data.

Input and output๐Ÿ”—

findingIdentityCity(map) -> string

Examples๐Ÿ”—

findingIdentityCity(inputs)

findingIdentityCity(inputs)

Output: "New York"

findingIdentityCompanyName๐Ÿ”—

Parses an identity finding record and returns the company name from the identity data.

Input and output๐Ÿ”—

findingIdentityCompanyName(map) -> string

Examples๐Ÿ”—

findingIdentityCompanyName(inputs)

findingIdentityCompanyName(inputs)

Output: "Example Corp"

findingIdentityCountry๐Ÿ”—

Parses an identity finding record and returns the country from the identity data.

Input and output๐Ÿ”—

findingIdentityCountry(map) -> string

Examples๐Ÿ”—

findingIdentityCountry(inputs)

findingIdentityCountry(inputs)

Output: "United States"

findingIdentityCreatedAt๐Ÿ”—

Parses an identity finding record and returns the creation timestamp from the identity data.

Input and output๐Ÿ”—

findingIdentityCreatedAt(map) -> string

Examples๐Ÿ”—

findingIdentityCreatedAt(inputs)

findingIdentityCreatedAt(inputs)

Output: "2024-01-15T10:30:00Z"

findingIdentityDepartment๐Ÿ”—

Parses an identity finding record and returns the department from the identity data.

Input and output๐Ÿ”—

findingIdentityDepartment(map) -> string

Examples๐Ÿ”—

findingIdentityDepartment(inputs)

findingIdentityDepartment(inputs)

Output: "Engineering"

findingIdentityDisplayName๐Ÿ”—

Parses an identity finding record and returns the display name from the identity data.

Input and output๐Ÿ”—

findingIdentityDisplayName(map) -> string

Examples๐Ÿ”—

findingIdentityDisplayName(inputs)

findingIdentityDisplayName(inputs)

Output: "John Doe"

findingIdentityEmails๐Ÿ”—

Parses an identity finding record and returns the email addresses from the identity data.

Input and output๐Ÿ”—

findingIdentityEmails(map) -> list

Examples๐Ÿ”—

findingIdentityEmails(inputs)

findingIdentityEmails(inputs)

Output: ["john.doe@example.com", "j.doe@example.com"]

findingIdentityEmployeeId๐Ÿ”—

Parses an identity finding record and returns the employee ID from the identity data.

Input and output๐Ÿ”—

findingIdentityEmployeeId(map) -> string

Examples๐Ÿ”—

findingIdentityEmployeeId(inputs)

findingIdentityEmployeeId(inputs)

Output: "EMP12345"

findingIdentityEmployeeType๐Ÿ”—

Parses an identity finding record and returns the employee type from the identity data.

Input and output๐Ÿ”—

findingIdentityEmployeeType(map) -> string

Examples๐Ÿ”—

findingIdentityEmployeeType(inputs)

findingIdentityEmployeeType(inputs)

Output: "Full-time"

findingIdentityExternalCreatedAt๐Ÿ”—

Parses an identity finding record and returns the external creation timestamp from the identity data.

Input and output๐Ÿ”—

findingIdentityExternalCreatedAt(map) -> string

Examples๐Ÿ”—

findingIdentityExternalCreatedAt(inputs)

findingIdentityExternalCreatedAt(inputs)

Output: "2024-01-15T10:30:00Z"

findingIdentityExternalId๐Ÿ”—

Parses an identity finding record and returns the external ID from the identity data.

Input and output๐Ÿ”—

findingIdentityExternalId(map) -> string

Examples๐Ÿ”—

findingIdentityExternalId(inputs)

findingIdentityExternalId(inputs)

Output: "ext-12345-abcd"

findingIdentityExternalUpdatedAt๐Ÿ”—

Parses an identity finding record and returns the external update timestamp from the identity data.

Input and output๐Ÿ”—

findingIdentityExternalUpdatedAt(map) -> string

Examples๐Ÿ”—

findingIdentityExternalUpdatedAt(inputs)

findingIdentityExternalUpdatedAt(inputs)

Output: "2024-01-20T15:45:00Z"

findingIdentityField๐Ÿ”—

Parses a finding and returns the value of the specified identity field.

Input and output๐Ÿ”—

findingIdentityField(map, string) -> bool

Examples๐Ÿ”—

findingIdentityField(inputs, 'status')

findingIdentityField(inputs, 'status')

Output: "ACTIVE"

findingIdentityField(inputs, 'nonexistent_field')

findingIdentityField(inputs, 'nonexistent_field')

Output:

findingIdentityGivenName๐Ÿ”—

Parses an identity finding record and returns the given name from the identity data.

Input and output๐Ÿ”—

findingIdentityGivenName(map) -> string

Examples๐Ÿ”—

findingIdentityGivenName(inputs)

findingIdentityGivenName(inputs)

Output: "John"

findingIdentityHasMfa๐Ÿ”—

Parses an identity finding record and returns whether MFA is enabled from the identity data.

Input and output๐Ÿ”—

findingIdentityHasMfa(map) -> bool

Examples๐Ÿ”—

findingIdentityHasMfa(inputs)

findingIdentityHasMfa(inputs)

Output: true

findingIdentityHasPasswordlessMfa๐Ÿ”—

Parses an identity finding record and returns whether passwordless MFA is enabled from the identity data.

Input and output๐Ÿ”—

findingIdentityHasPasswordlessMfa(map) -> bool

Examples๐Ÿ”—

findingIdentityHasPasswordlessMfa(inputs)

findingIdentityHasPasswordlessMfa(inputs)

Output: false

findingIdentityHireDate๐Ÿ”—

Parses an identity finding record and returns the hire date from the identity data.

Input and output๐Ÿ”—

findingIdentityHireDate(map) -> string

Examples๐Ÿ”—

findingIdentityHireDate(inputs)

findingIdentityHireDate(inputs)

Output: "2023-06-01"

findingIdentityIsAdmin๐Ÿ”—

Parses an identity finding record and returns whether the identity has admin privileges.

Input and output๐Ÿ”—

findingIdentityIsAdmin(map) -> bool

Examples๐Ÿ”—

findingIdentityIsAdmin(inputs)

findingIdentityIsAdmin(inputs)

Output: false

findingIdentityIsGuest๐Ÿ”—

Parses an identity finding record and returns whether the identity is a guest user.

Input and output๐Ÿ”—

findingIdentityIsGuest(map) -> bool

Examples๐Ÿ”—

findingIdentityIsGuest(inputs)

findingIdentityIsGuest(inputs)

Output: false

findingIdentityLastActiveAt๐Ÿ”—

Parses an identity finding record and returns the last active timestamp from the identity data.

Input and output๐Ÿ”—

findingIdentityLastActiveAt(map) -> string

Examples๐Ÿ”—

findingIdentityLastActiveAt(inputs)

findingIdentityLastActiveAt(inputs)

Output: "2024-09-01T14:30:00Z"

findingIdentityLastPasswordChangeAt๐Ÿ”—

Parses an identity finding record and returns the last password change timestamp from the identity data.

Input and output๐Ÿ”—

findingIdentityLastPasswordChangeAt(map) -> string

Examples๐Ÿ”—

findingIdentityLastPasswordChangeAt(inputs)

findingIdentityLastPasswordChangeAt(inputs)

Output: "2024-08-15T09:00:00Z"

findingIdentityLeaveDate๐Ÿ”—

Parses an identity finding record and returns the leave date from the identity data.

Input and output๐Ÿ”—

findingIdentityLeaveDate(map) -> string

Examples๐Ÿ”—

findingIdentityLeaveDate(inputs)

findingIdentityLeaveDate(inputs)

Output: "2025-01-31"

findingIdentityLocation๐Ÿ”—

Parses an identity finding record and returns the location from the identity data.

Input and output๐Ÿ”—

findingIdentityLocation(map) -> string

Examples๐Ÿ”—

findingIdentityLocation(inputs)

findingIdentityLocation(inputs)

Output: "New York Office"

findingIdentityManager๐Ÿ”—

Parses an identity finding record and returns the manager from the identity data.

Input and output๐Ÿ”—

findingIdentityManager(map) -> string

Examples๐Ÿ”—

findingIdentityManager(inputs)

findingIdentityManager(inputs)

Output: "Jane Smith"

findingIdentityMfaMethods๐Ÿ”—

Parses an identity finding record and returns the MFA methods from the identity data.

Input and output๐Ÿ”—

findingIdentityMfaMethods(map) -> list

Examples๐Ÿ”—

findingIdentityMfaMethods(inputs)

findingIdentityMfaMethods(inputs)

Output: ["SMS", "Authenticator App"]

findingIdentityOfficeLocation๐Ÿ”—

Parses an identity finding record and returns the office location from the identity data.

Input and output๐Ÿ”—

findingIdentityOfficeLocation(map) -> string

Examples๐Ÿ”—

findingIdentityOfficeLocation(inputs)

findingIdentityOfficeLocation(inputs)

Output: "Building A, Floor 5"

findingIdentityOfficeZipCode๐Ÿ”—

Parses an identity finding record and returns the office zip code from the identity data.

Input and output๐Ÿ”—

findingIdentityOfficeZipCode(map) -> string

Examples๐Ÿ”—

findingIdentityOfficeZipCode(inputs)

findingIdentityOfficeZipCode(inputs)

Output: "10001"

findingIdentityPhoneNumbers๐Ÿ”—

Parses an identity finding record and returns the phone numbers from the identity data.

Input and output๐Ÿ”—

findingIdentityPhoneNumbers(map) -> list

Examples๐Ÿ”—

findingIdentityPhoneNumbers(inputs)

findingIdentityPhoneNumbers(inputs)

Output: ["+1-555-0123", "+1-555-0124"]

findingIdentityPrimaryDomain๐Ÿ”—

Parses an identity finding record and returns the primary domain from the identity data.

Input and output๐Ÿ”—

findingIdentityPrimaryDomain(map) -> string

Examples๐Ÿ”—

findingIdentityPrimaryDomain(inputs)

findingIdentityPrimaryDomain(inputs)

Output: "example.com"

findingIdentityPrimaryEntityId๐Ÿ”—

Parses an identity finding record and returns the primary entity ID from the identity data.

Input and output๐Ÿ”—

findingIdentityPrimaryEntityId(map) -> string

Examples๐Ÿ”—

findingIdentityPrimaryEntityId(inputs)

findingIdentityPrimaryEntityId(inputs)

Output: "entity-12345-abcd"

findingIdentityPrimaryMfaMethod๐Ÿ”—

Parses an identity finding record and returns the primary MFA method from the identity data.

Input and output๐Ÿ”—

findingIdentityPrimaryMfaMethod(map) -> string

Examples๐Ÿ”—

findingIdentityPrimaryMfaMethod(inputs)

findingIdentityPrimaryMfaMethod(inputs)

Output: "Authenticator App"

findingIdentityPrimaryUsername๐Ÿ”—

Parses an identity finding record and returns the primary username from the identity data.

Input and output๐Ÿ”—

findingIdentityPrimaryUsername(map) -> string

Examples๐Ÿ”—

findingIdentityPrimaryUsername(inputs)

findingIdentityPrimaryUsername(inputs)

Output: "john.doe"

findingIdentityProperties๐Ÿ”—

Parses an identity finding record and returns the properties map from the identity data.

Input and output๐Ÿ”—

findingIdentityProperties(map) -> map

Examples๐Ÿ”—

findingIdentityProperties(inputs)

findingIdentityProperties(inputs)

Output: {"customAttribute1": "value1", "customAttribute2": "value2"}

findingIdentityProviderId๐Ÿ”—

Parses an identity finding record and returns the provider ID from the identity data.

Input and output๐Ÿ”—

findingIdentityProviderId(map) -> string

Examples๐Ÿ”—

findingIdentityProviderId(inputs)

findingIdentityProviderId(inputs)

Output: "provider-azure-ad-12345"

findingIdentityRaw๐Ÿ”—

Parses an identity finding record and returns the raw identity data.

Input and output๐Ÿ”—

findingIdentityRaw(map) -> map

Examples๐Ÿ”—

findingIdentityRaw(inputs)

findingIdentityRaw(inputs)

Output: {"id": "user-123", "displayName": "John Doe", "mail": "john.doe@example.com"}

findingIdentityRegion๐Ÿ”—

Parses an identity finding record and returns the region from the identity data.

Input and output๐Ÿ”—

findingIdentityRegion(map) -> string

Examples๐Ÿ”—

findingIdentityRegion(inputs)

findingIdentityRegion(inputs)

Output: "North America"

findingIdentityStatus๐Ÿ”—

Parses an identity finding record and returns the status from the identity data.

Input and output๐Ÿ”—

findingIdentityStatus(map) -> string

Examples๐Ÿ”—

findingIdentityStatus(inputs)

findingIdentityStatus(inputs)

Output: "ACTIVE"

findingIdentitySurname๐Ÿ”—

Parses an identity finding record and returns the surname from the identity data.

Input and output๐Ÿ”—

findingIdentitySurname(map) -> string

Examples๐Ÿ”—

findingIdentitySurname(inputs)

findingIdentitySurname(inputs)

Output: "Doe"

findingIdentityTenant๐Ÿ”—

Parses an identity finding record and returns the tenant from the identity data.

Input and output๐Ÿ”—

findingIdentityTenant(map) -> int

Examples๐Ÿ”—

findingIdentityTenant(inputs)

findingIdentityTenant(inputs)

Output: 12345

findingIdentityTitle๐Ÿ”—

Parses an identity finding record and returns the job title from the identity data.

Input and output๐Ÿ”—

findingIdentityTitle(map) -> string

Examples๐Ÿ”—

findingIdentityTitle(inputs)

findingIdentityTitle(inputs)

Output: "Software Engineer"

findingIdentityUpdatedAt๐Ÿ”—

Parses an identity finding record and returns the update timestamp from the identity data.

Input and output๐Ÿ”—

findingIdentityUpdatedAt(map) -> string

Examples๐Ÿ”—

findingIdentityUpdatedAt(inputs)

findingIdentityUpdatedAt(inputs)

Output: "2024-09-01T12:00:00Z"

findingIdentityUsageLocation๐Ÿ”—

Parses an identity finding record and returns the usage location from the identity data.

Input and output๐Ÿ”—

findingIdentityUsageLocation(map) -> string

Examples๐Ÿ”—

findingIdentityUsageLocation(inputs)

findingIdentityUsageLocation(inputs)

Output: "US"

findingIdentityUsernames๐Ÿ”—

Parses an identity finding record and returns the usernames from the identity data.

Input and output๐Ÿ”—

findingIdentityUsernames(map) -> list

Examples๐Ÿ”—

findingIdentityUsernames(inputs)

findingIdentityUsernames(inputs)

Output: ["john.doe", "jdoe", "john.doe@example.com"]

findingIdentityZipCode๐Ÿ”—

Parses an identity finding record and returns the zip code from the identity data.

Input and output๐Ÿ”—

findingIdentityZipCode(map) -> string

Examples๐Ÿ”—

findingIdentityZipCode(inputs)

findingIdentityZipCode(inputs)

Output: "10001"

findingLastModified๐Ÿ”—

Parses an identity finding record and returns the last modified timestamp.

Input and output๐Ÿ”—

findingLastModified(map) -> string

Examples๐Ÿ”—

findingLastModified(inputs)

findingLastModified(inputs)

Output: "2025-04-28T16:57:49.591956Z"

findingLastSeen๐Ÿ”—

Parses an identity finding record and returns the last seen timestamp.

Input and output๐Ÿ”—

findingLastSeen(map) -> string

Examples๐Ÿ”—

findingLastSeen(inputs)

findingLastSeen(inputs)

Output: "2025-04-22T16:57:49.591956Z"

findingOtherReferences๐Ÿ”—

Parses an identity finding record and returns the other references list. An optional second argument returns a list of specific entries.

Input and output๐Ÿ”—

findingOtherReferences(map) -> list
findingOtherReferences(map, string) -> list

Examples๐Ÿ”—

findingOtherReferences(inputs)

findingOtherReferences(inputs)

Output: [{"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}]

findingOtherReferences(inputs, 'type')

findingOtherReferences(inputs, 'type')

Output: ["microsoft.graph.application"]

findingOtherReferences(inputs, 'id')

findingOtherReferences(inputs, 'id')

Output: ["7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]

findingOtherReferences(inputs, 'logicalType')

findingOtherReferences(inputs, 'logicalType')

Output: ["UNKNOWN"]

findingOtherReferences(inputs, 'derivedType')

findingOtherReferences(inputs, 'derivedType')

Output: ["APP"]

findingOtherReferences(inputs, 'displayName')

findingOtherReferences(inputs, 'displayName')

Output: ["soanceawebapp"]

findingOtherReferences(inputs, 'externalLink')

findingOtherReferences(inputs, 'externalLink')

Output: ["https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]

findingPrimaryReference๐Ÿ”—

Parses an identity finding record and returns the primary reference map. An optional second argument returns a specific entry.

Input and output๐Ÿ”—

findingPrimaryReference(map) -> map
findingPrimaryReference(map, string) -> string

Examples๐Ÿ”—

findingPrimaryReference(inputs)

findingPrimaryReference(inputs)

Output: {"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}

findingPrimaryReference(inputs, 'type')

findingPrimaryReference(inputs, 'type')

Output: "microsoft.graph.servicePrincipal"

findingPrimaryReference(inputs, 'id')

findingPrimaryReference(inputs, 'id')

Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"

findingPrimaryReference(inputs, 'logicalType')

findingPrimaryReference(inputs, 'logicalType')

Output: "IDENTITY_SERVICE_PRINCIPAL"

findingPrimaryReference(inputs, 'derivedType')

findingPrimaryReference(inputs, 'derivedType')

Output: "APP"

findingPrimaryReference(inputs, 'displayName')

findingPrimaryReference(inputs, 'displayName')

Output: "soanceawebapp"

findingPrimaryReference(inputs, 'externalLink')

findingPrimaryReference(inputs, 'externalLink')

Output: "https://portal.azure.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/e98c0bf1-f226-4465-940f-696a79e7bdc6/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"

findingResult๐Ÿ”—

Parses an identity finding record and returns the result.

Input and output๐Ÿ”—

findingResult(map) -> string

Examples๐Ÿ”—

findingResult(inputs)

findingResult(inputs)

Output: "{\"replyUrls\":[\"https://soanceawebapp.azurewebsites.net/.auth/login/aad/callback\"]}"

findingSeverity๐Ÿ”—

Parses an identity finding record and returns the severity label (INFO, LOW, MEDIUM, HIGH, CRITICAL).

An optional second argument of true returns the severity as a double (0.0-1.0).

Input and output๐Ÿ”—

findingSeverity(map) -> string
findingSeverity(map, bool) -> double

Examples๐Ÿ”—

findingSeverity(inputs)

findingSeverity(inputs)

Output: "CRITICAL"

findingSeverity(inputs, true)

findingSeverity(inputs, true)

Output: "0.800000011920929"

findingSource๐Ÿ”—

Parses an identity finding record and returns the source map. An optional second argument returns a specific entry.

Input and output๐Ÿ”—

findingSource(map) -> map
findingSource(map, string) -> any

Examples๐Ÿ”—

findingSource(inputs)

findingSource(inputs)

Output: {'id':'63258f26-1d39-4d69-9e85-e409244d9c97','resolved':{...},'type':'IDENTITY_PROVIDER'}

findingSource(inputs, 'type')

findingSource(inputs, 'type')

Output: "IDENTITY_PROVIDER"

findingSource(inputs, 'id')

findingSource(inputs, 'id')

Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"

findingSource(inputs, 'resolved')

findingSource(inputs, 'resolved')

Output: {'createdAt':'2025-02-03T08:32:21.80852Z','disabledAt':null,'expiration':'2026-06-06T05:00:03Z',...}

findingStatus๐Ÿ”—

Parses an identity finding record and returns the status.

Input and output๐Ÿ”—

findingStatus(map) -> string

Examples๐Ÿ”—

findingStatus(inputs)

findingStatus(inputs)

Output: "OPEN"

findingStatusComments๐Ÿ”—

Parses an identity finding record and returns the status comments.

Input and output๐Ÿ”—

findingStatusComments(map) -> string

Examples๐Ÿ”—

findingStatusComments(inputs)

findingStatusComments(inputs)

Output: "issue resolved"

findingTenantId๐Ÿ”—

Parses an identity finding record and returns the tenant ID.

Input and output๐Ÿ”—

findingTenantId(map) -> string

Examples๐Ÿ”—

findingTenantId(inputs)

findingTenantId(inputs)

Output: "12345"

findingsStatusCommentsUserId๐Ÿ”—

Parses an identity finding record and returns the user ID that added the status comments.

Input and output๐Ÿ”—

findingsStatusCommentsUserId(map) -> string

Examples๐Ÿ”—

findingsStatusCommentsUserId(inputs)

findingsStatusCommentsUserId(inputs)

Output: "3f59db3b-6b9c-4fb8-a26d-4c53fb334b4e"

first (optional element)๐Ÿ”—

Returns an optional containing the first element of a list, or optional.none() if the list is empty.

Input and output๐Ÿ”—

list.first() -> optional(T)

Returns an optional containing the first element of a list. If the list is empty, returns optional.none().

Use cases๐Ÿ”—

Safe head access.

[1, 2, 3].first().orValue(0)

Get the first element or return a default value.

Check if empty.

items.first().hasValue()

Check whether the list has elements.

Process the first item.

tasks.first().optMap(t, t.priority)

Get the priority of the first task.

Conditional access.

results.first().orValue('No results')

Safely access the first result or return a message.

Chained processing.

data.filter(x, x > 0).first().orValue(-1)

Filter the data, then get the first result.

Validation.

!items.first().hasValue() ? 'Empty list' : 'Has items'

Check whether the list is empty.

Notes๐Ÿ”—

  • Returns optional(T), where T is the element type.
  • Safely returns optional.none() for empty lists.
  • Is more expressive than list[?0].
  • Use .orValue() to provide a default.
  • Doesn't modify the original list.

Examples๐Ÿ”—

[1, 2, 3].first().orValue(0)

[1, 2, 3].first().orValue(0)

Output: 1

Get the first element.

[].first().hasValue()

[].first().hasValue()

Output: false

Check an empty list.

[].first().orValue(99)

[].first().orValue(99)

Output: 99

Use the default value for an empty list.

['a', 'b', 'c'].first().value()

['a', 'b', 'c'].first().value()

Output: 'a'

Extract the first string.

first (list elements)๐Ÿ”—

Returns the first N elements of a list.

Input and output๐Ÿ”—

first(list, int) -> list

Examples๐Ÿ”—

first(["a", "c", "b"], 1)

first(["a", "c", "b"], 1)

Output: ["a"]

flatten๐Ÿ”—

Returns a list where all nested lists are combined into a single top-level list.

Input and output๐Ÿ”—

flatten(list) -> list

Examples๐Ÿ”—

flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])

flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])

Output: ["row1col1", "row1col2", "row2col1", "row2col2"]

format (string)๐Ÿ”—

Formats the string using printf-style formatting with the provided arguments.

Input and output๐Ÿ”—

string.format(list) -> string

Formats the string using printf-style format specifiers with values from the list.

Common format specifiers:

  • %s: String.
  • %d: Integer.
  • %f: Floating-point number.
  • %%: Literal percent sign.

Examples๐Ÿ”—

'Hello %s'.format(['World'])

'Hello %s'.format(['World'])

Output: "Hello World"

'Value: %d, Name: %s'.format([42, 'test'])

'Value: %d, Name: %s'.format([42, 'test'])

Output: "Value: 42, Name: test"

'Pi: %.2f'.format([3.14159])

'Pi: %.2f'.format([3.14159])

Output: "Pi: 3.14"

format (timestamp)๐Ÿ”—

Returns the string representation of the timestamp using the provided format. See Constants for a list of supported formats.

Input and output๐Ÿ”—

format(timestamp, string) -> string

Examples๐Ÿ”—

"1/1/2012".toTimestamp().format("layout")

"1/1/2012".toTimestamp().format("layout")

Output: 2012-01-01T00:00:00Z

"1/1/2012".toTimestamp().format("dateonly")

"1/1/2012".toTimestamp().format("dateonly")

Output: 2012-01-01

"1/1/2012".toTimestamp().format("Mon")

"1/1/2012".toTimestamp().format("Mon")

Output: Sun

generateString๐Ÿ”—

Returns a randomly generated string with the length specified in the first argument and the characters or alphabet provided in the second argument.

Input and output๐Ÿ”—

generateString(int, string) -> string

Examples๐Ÿ”—

generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")

generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")

Output: aPsd2

groupBy๐Ÿ”—

Returns a list of map elements grouped by one or more paths and a corresponding count of each grouping.

The first argument is the list to group. The second argument is a list of paths to group by. The optional third argument sorts the list in ascending (asc) or descending (desc) order. The default is ascending.

Input and output๐Ÿ”—

groupBy(list, list, string) -> list

Examples๐Ÿ”—

groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")

groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")

Output: [{"amap.host": "test1", "amap.title": "test", "count": 1}, {"amap.host": "test", "amap.title": "test", "count": 2}]

has๐Ÿ”—

Validates that a key exists, is defined, and has a non-null value.

This macro also supports checking a map for one or more paths. An optional third argument specifies the separator used in the paths.

Input and output๐Ÿ”—

has(map, string) -> bool

Examples๐Ÿ”—

has(inputs, "key")

has(inputs, "key")

Output: true

hasValue๐Ÿ”—

Returns true if the optional contains a value. Otherwise, returns false.

Input and output๐Ÿ”—

optional(T).hasValue() -> bool

Checks whether an optional contains a value.

Use cases๐Ÿ”—

Check before access.

obj.?field.hasValue() ? obj.field : 'default'

Safely check for a value before accessing it.

Validate input.

input.?userId.hasValue()

Check whether the field exists.

Use guard clauses.

!optional.none().hasValue()

Output: true

Verify that an optional is empty.

Optional chaining.

data[?'key'].hasValue() && data['key'] > 10

Check that a value exists before comparing it.

Filter present values.

items.filter(i, i.?metadata.hasValue())

Keep only items that have metadata.

Notes๐Ÿ”—

  • Returns a Boolean value (true or false).
  • Is safe to call on any optional.
  • Use before calling .value() to avoid errors.
  • Is commonly used with conditional expressions.
  • Provides an alternative to checking for errors.

Examples๐Ÿ”—

optional.of(42).hasValue()

optional.of(42).hasValue()

Output: true

The optional has a value.

optional.none().hasValue()

optional.none().hasValue()

Output: false

The optional has no value.

{'a': 1}[?'a'].hasValue()

{'a': 1}[?'a'].hasValue()

Output: true

The key exists.

{'a': 1}[?'b'].hasValue()

{'a': 1}[?'b'].hasValue()

Output: false

The key is missing.

[1, 2, 3][?0].hasValue()

[1, 2, 3][?0].hasValue()

Output: true

The index exists.

[1, 2, 3][?10].hasValue()

[1, 2, 3][?10].hasValue()

Output: false

The index is out of bounds.

hostnames๐Ÿ”—

Parses an alert, entity, or asset and returns the hostnames found.

Input and output๐Ÿ”—

hostnames(map) -> list

Examples๐Ÿ”—

hostnames(inputs)

hostnames(inputs)

Output: ["alert_hostname", "entity_hostname", "asset_hostname"]

indexOf๐Ÿ”—

Returns the index of the first occurrence of a substring.

Input and output๐Ÿ”—

string.indexOf(string) -> int
string.indexOf(string, int) -> int

Returns the zero-based index of the first occurrence of the substring.

Returns -1 if the substring isn't found.

The optional second argument specifies the starting position for the search.

Examples๐Ÿ”—

'hello world'.indexOf('world')

'hello world'.indexOf('world')

Output: 6

'hello world'.indexOf('o')

'hello world'.indexOf('o')

Output: 4

'hello world'.indexOf('o', 5)

'hello world'.indexOf('o', 5)

Output: 7

'hello world'.indexOf('xyz')

'hello world'.indexOf('xyz')

Output: -1

investigationArchivedAt๐Ÿ”—

Parses an investigation record and returns the date and time it was archived.

Input and output๐Ÿ”—

investigationArchivedAt(map) -> string

Examples๐Ÿ”—

investigationArchivedAt(inputs)

investigationArchivedAt(inputs)

Output: "2024-06-20T17:57:46.700164Z"

investigationAssigneeId๐Ÿ”—

Parses an investigation record and returns the ID of the assignee.

Input and output๐Ÿ”—

investigationAssigneeId(map) -> string

Examples๐Ÿ”—

investigationAssigneeId(inputs)

investigationAssigneeId(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

investigationCloseReason๐Ÿ”—

Parses an investigation record and returns the reason it was closed.

Input and output๐Ÿ”—

investigationCloseReason(map) -> string

Examples๐Ÿ”—

investigationCloseReason(inputs)

investigationCloseReason(inputs)

Output: "reason for closing"

investigationComment๐Ÿ”—

Parses an investigation record and returns the comment associated with it.

Input and output๐Ÿ”—

investigationComment(map) -> string

Examples๐Ÿ”—

investigationComment(inputs)

investigationComment(inputs)

Output: "This is a sample comment for the investigation."

investigationCommentAuthorId๐Ÿ”—

Parses an investigation record and returns the ID of the author of the comment.

Input and output๐Ÿ”—

investigationCommentAuthorId(map) -> string

Examples๐Ÿ”—

investigationCommentAuthorId(inputs)

investigationCommentAuthorId(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

investigationCommentCreatedAt๐Ÿ”—

Parses an investigation record and returns the date and time the comment was created.

Input and output๐Ÿ”—

investigationCommentCreatedAt(map) -> string

Examples๐Ÿ”—

investigationCommentCreatedAt(inputs)

investigationCommentCreatedAt(inputs)

Output: "2024-06-20T17:57:46.700164Z"

investigationCommentMentions๐Ÿ”—

Parses an investigation record and returns a list of mentions in the comment.

Input and output๐Ÿ”—

investigationCommentMentions(map) -> list

Examples๐Ÿ”—

investigationCommentMentions(inputs)

investigationCommentMentions(inputs)

Output: ["@secureworks", "@dac1ed31-111-4809-9cc9-9f99b6e"]

investigationCommentOperation๐Ÿ”—

Parses an investigation record and returns the operation type of the comment.

Input and output๐Ÿ”—

investigationCommentOperation(map) -> string

Examples๐Ÿ”—

investigationCommentOperation(inputs)

investigationCommentOperation(inputs)

Output: "create"

investigationContributorIds๐Ÿ”—

Parses an investigation record and returns a list of contributor IDs.

Input and output๐Ÿ”—

investigationContributorIds(map) -> list

Examples๐Ÿ”—

investigationContributorIds(inputs)

investigationContributorIds(inputs)

Output: ["dac1ed31-111-4809-9cc9-9f99b6e", "ff0197b0@clients"]

investigationCreatedAt๐Ÿ”—

Parses an investigation record and returns the date and time it was created.

Input and output๐Ÿ”—

investigationCreatedAt(map) -> string

Examples๐Ÿ”—

investigationCreatedAt(inputs)

investigationCreatedAt(inputs)

Output: "2024-06-20T17:57:45.592464Z"

investigationCreatedById๐Ÿ”—

Parses an investigation record and returns the ID of the user that created it.

Input and output๐Ÿ”—

investigationCreatedById(map) -> string

Examples๐Ÿ”—

investigationCreatedById(inputs)

investigationCreatedById(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

investigationCreatedByPartner๐Ÿ”—

Parses an investigation record and returns true if it was created by a parent of the tenant.

Input and output๐Ÿ”—

investigationCreatedByPartner(map) -> bool

Examples๐Ÿ”—

investigationCreatedByPartner(inputs)

investigationCreatedByPartner(inputs)

Output: false

investigationFieldChanged๐Ÿ”—

Parses an investigation record and returns true if the provided field was modified.

Input and output๐Ÿ”—

investigationFieldChanged(map, string) -> bool

Examples๐Ÿ”—

investigationFieldChanged(inputs, 'priority')

investigationFieldChanged(inputs, 'priority')

Output: true

investigationFieldChanged(inputs, 'nonexistent_field')

investigationFieldChanged(inputs, 'nonexistent_field')

Output: false

investigationId๐Ÿ”—

Parses an investigation record and returns the ID.

Input and output๐Ÿ”—

investigationId(map) -> string

Examples๐Ÿ”—

investigationId(inputs)

investigationId(inputs)

Output: "a251201f-9a26-4cd5-81f6-20509999933d"

investigationKeyFindings๐Ÿ”—

Parses an investigation record and returns the key findings.

Input and output๐Ÿ”—

investigationKeyFindings(map) -> string

Examples๐Ÿ”—

investigationKeyFindings(inputs)

investigationKeyFindings(inputs)

Output: "Sample Investigation Key Findings"

investigationPriority๐Ÿ”—

Parses an investigation record and returns the priority as a word (Low, Medium, High, or Critical).

An optional second argument of true returns the priority as an integer (1-4).

Input and output๐Ÿ”—

investigationPriority(map) -> string
investigationPriority(map, bool) -> int

Examples๐Ÿ”—

investigationPriority(inputs)

investigationPriority(inputs)

Output: "High"

investigationPriority(inputs, true)

investigationPriority(inputs, true)

Output: 3

investigationProcessingStatus๐Ÿ”—

Parses an investigation record and returns the processing status map.

Input and output๐Ÿ”—

investigationProcessingStatus(map) -> map

Examples๐Ÿ”—

investigationProcessingStatus(inputs)

investigationProcessingStatus(inputs)

Output: {"alerts": "SUCCESS", "assets": "SUCCESS", "events": "SUCCESS"}

investigationRuleId๐Ÿ”—

Parses an investigation record and returns the auto investigation rule ID that created it.

Input and output๐Ÿ”—

investigationRuleId(map) -> string

Examples๐Ÿ”—

investigationRuleId(inputs)

investigationRuleId(inputs)

Output: "12345"

investigationStatus๐Ÿ”—

Parses an investigation record and returns the status.

Input and output๐Ÿ”—

investigationStatus(map) -> string
investigationStatus(map, string) -> string

Examples๐Ÿ”—

investigationStatus(inputs)

investigationStatus(inputs)

Output: "OPEN"

investigationStatus(inputs, "v1")

investigationStatus(inputs, "v1")

Output: "Open"

investigationTenantId๐Ÿ”—

Parses an investigation record and returns the ID of the tenant.

Input and output๐Ÿ”—

investigationTenantId(map) -> string

Examples๐Ÿ”—

investigationTenantId(inputs)

investigationTenantId(inputs)

Output: "12345"

investigationThirdPartyId๐Ÿ”—

Parses an investigation record and returns the ID of a third-party record associated with it.

Input and output๐Ÿ”—

investigationThirdPartyId(map) -> string

Examples๐Ÿ”—

investigationThirdPartyId(inputs)

investigationThirdPartyId(inputs)

Output: "bdf9f35a8383121055c9e330ceaad3b8"

investigationThirdPartyType๐Ÿ”—

Parses an investigation record and returns the type of a third-party record associated with it.

Input and output๐Ÿ”—

investigationThirdPartyType(map) -> string

Examples๐Ÿ”—

investigationThirdPartyType(inputs)

investigationThirdPartyType(inputs)

Output: "SNOW"

investigationTitle๐Ÿ”—

Parses an investigation record and returns the title.

Input and output๐Ÿ”—

investigationTitle(map) -> string

Examples๐Ÿ”—

investigationTitle(inputs)

investigationTitle(inputs)

Output: "Taegis Watchlist Investigation"

investigationType๐Ÿ”—

Parses an investigation record and returns the type.

An optional second argument of 'v1' or 'v2' converts the type. The default is 'v2'.

Input and output๐Ÿ”—

investigationType(map) -> string
investigationType(map, string) -> string

Examples๐Ÿ”—

investigationType(inputs)

investigationType(inputs)

Output: "SECURITY_INVESTIGATION"

investigationType(inputs, 'v1')

investigationType(inputs, 'v1')

Output: "Security Investigation"

investigationUpdatedAt๐Ÿ”—

Parses an investigation record and returns the date and time of the last update.

Input and output๐Ÿ”—

investigationUpdatedAt(map) -> string

Examples๐Ÿ”—

investigationUpdatedAt(inputs)

investigationUpdatedAt(inputs)

Output: "2024-06-20T17:57:46.700164Z"

investigationUpdatedById๐Ÿ”—

Parses an investigation record and returns the ID of the user that last updated it.

Input and output๐Ÿ”—

investigationUpdatedById(map) -> string

Examples๐Ÿ”—

investigationUpdatedById(inputs)

investigationUpdatedById(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

ipInNetwork๐Ÿ”—

Returns true if the first argument IP address is in one or more of the second argument IP network ranges.

The second argument is represented as a list of networks in CIDR notation.

Input and output๐Ÿ”—

ipInNetwork(string, list) -> bool

Examples๐Ÿ”—

ipInNetwork("10.1.1.1", ["10.0.0.0/8"])

ipInNetwork("10.1.1.1", ["10.0.0.0/8"])

Output: true

ipInNetwork("192.168.1.1", ["10.0.0.0/8"])

ipInNetwork("192.168.1.1", ["10.0.0.0/8"])

Output: false

ipsv4๐Ÿ”—

Parses an alert or entity and returns a list of IPv4 addresses if found.

Input and output๐Ÿ”—

ipsv4(map) -> list

Examples๐Ÿ”—

ipsv4(inputs)

ipsv4(inputs)

Output: ["127.0.0.111", "4.3.2.1", "1.2.3.4", "9.8.7.6", "6.7.8.9"]

isCaseClosed๐Ÿ”—

Parses a case record and returns whether the case is closed.

Input and output๐Ÿ”—

isCaseClosed(map) -> bool

Examples๐Ÿ”—

isCaseClosed(inputs)

isCaseClosed(inputs)

Output: false

isCaseVisibleToCustomers๐Ÿ”—

Parses a case record and returns whether the case is visible to customers.

Input and output๐Ÿ”—

isCaseVisibleToCustomers(map) -> bool

Examples๐Ÿ”—

isCaseVisibleToCustomers(inputs)

isCaseVisibleToCustomers(inputs)

Output: true

isDomain๐Ÿ”—

Returns true if the provided string argument represents a valid domain.

Input and output๐Ÿ”—

isDomain(string) -> bool

Examples๐Ÿ”—

isDomain("example.com")

isDomain("example.com")

Output: true

isDomain("not_a_domain")

isDomain("not_a_domain")

Output: false

isEmail๐Ÿ”—

Returns true if the provided string argument represents a valid email address.

Input and output๐Ÿ”—

isEmail(string) -> bool

Examples๐Ÿ”—

isEmail("sara@example.com")

isEmail("sara@example.com")

Output: true

isEmail("not_an_email")

isEmail("not_an_email")

Output: false

isIP๐Ÿ”—

Returns true if the provided string argument represents a valid IPv4 address.

Input and output๐Ÿ”—

isIP(string) -> bool

Examples๐Ÿ”—

isIP("127.0.0.1")

isIP("127.0.0.1")

Output: true

isIP("not_an_ip")

isIP("not_an_ip")

Output: false

isPrivateIP๐Ÿ”—

Returns true if the provided string argument represents a private (RFC-1918), link-local, or loopback IPv4 address.

Input and output๐Ÿ”—

isPrivateIP(string) -> bool

Examples๐Ÿ”—

isPrivateIP("192.168.1.1")

isPrivateIP("192.168.1.1")

Output: true

isPrivateIP("8.8.8.8")

isPrivateIP("8.8.8.8")

Output: false

isURL๐Ÿ”—

Returns true if the provided string argument represents a valid Uniform Resource Locator (URL).

Input and output๐Ÿ”—

isURL(string) -> bool
isURL(list) -> bool

Examples๐Ÿ”—

isURL("https://example.com")

isURL("https://example.com")

Output: true

isURL("not_a_url")

isURL("not_a_url")

Output: false

isUUID๐Ÿ”—

Returns true if the provided string argument represents a valid Universally Unique Identifier (UUID).

Input and output๐Ÿ”—

isUUID(string) -> bool

Examples๐Ÿ”—

isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")

isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")

Output: true

isUUID("not_a_uuid")

isUUID("not_a_uuid")

Output: false

join๐Ÿ”—

Combines the elements of a list into a string using the provided separator.

The default separator is a comma character.

Input and output๐Ÿ”—

join(list) -> string
join(list, string) -> string

Examples๐Ÿ”—

join(["a", 1, true])

join(["a", 1, true])

Output: "a,1,true"

join(["a", 1, true], ".")

join(["a", 1, true], ".")

Output: "a.1.true"

keys๐Ÿ”—

Returns a list of top-level keys from a map.

Input and output๐Ÿ”—

keys(map) -> list

Examples๐Ÿ”—

keys({"foo": "bar", "a": "b"})

keys({"foo": "bar", "a": "b"})

Output: ["foo", "a"]

last (list elements)๐Ÿ”—

Returns the last N elements of a list.

Input and output๐Ÿ”—

last(list, int) -> list

Examples๐Ÿ”—

last(["a", "c", "b"], 2)

last(["a", "c", "b"], 2)

Output: ["c", "b"]

last (optional element)๐Ÿ”—

Returns an optional containing the last element of a list, or optional.none() if the list is empty.

Input and output๐Ÿ”—

list.last() -> optional(T)

Returns an optional containing the last element of a list.

If the list is empty, returns optional.none().

Use cases๐Ÿ”—

Safe tail access.

[1, 2, 3].last().orValue(0)

Get the last element or return a default value.

Most recent item.

events.last().optMap(e, e.timestamp)

Get the timestamp of the latest event.

Check if empty.

items.last().hasValue()

Check whether the list has elements.

Latest value.

history.last().orValue('No history')

Get the most recent value or a default message.

End of sequence.

sequence.last().orValue(-1) > threshold

Check the last value against a threshold.

Validation.

results.last().hasValue() ? 'Complete' : 'Empty'

Check the state of the list.

Notes๐Ÿ”—

  • Returns optional(T), where T is the element type.
  • Safely returns optional.none() for empty lists.
  • Is more expressive than list[?list.size()-1].
  • Use .orValue() to provide a default.
  • Doesn't modify the original list.

Examples๐Ÿ”—

[1, 2, 3].last().orValue(0)

[1, 2, 3].last().orValue(0)

Output: 3

Get the last element.

[].last().hasValue()

[].last().hasValue()

Output: false

Check an empty list.

[].last().orValue(99)

[].last().orValue(99)

Output: 99

Use the default value for an empty list.

['a', 'b', 'c'].last().value()

['a', 'b', 'c'].last().value()

Output: 'c'

Extract the last string.

lastIndexOf๐Ÿ”—

Returns the index of the last occurrence of a substring.

Input and output๐Ÿ”—

string.lastIndexOf(string) -> int
string.lastIndexOf(string, int) -> int

Returns the zero-based index of the last occurrence of the substring.

Returns -1 if the substring isn't found.

The optional second argument specifies the ending position for the search.

Examples๐Ÿ”—

'hello world'.lastIndexOf('o')

'hello world'.lastIndexOf('o')

Output: 7

'hello world'.lastIndexOf('l')

'hello world'.lastIndexOf('l')

Output: 9

'hello world'.lastIndexOf('o', 6)

'hello world'.lastIndexOf('o', 6)

Output: 4

'hello world'.lastIndexOf('xyz')

'hello world'.lastIndexOf('xyz')

Output: -1

list๐Ÿ”—

Converts input to a list.

Input and output๐Ÿ”—

list(any) -> list

Examples๐Ÿ”—

list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))

list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))

Output: [1, 3]

lists.range๐Ÿ”—

Generates a list of sequential integers from 0 to n-1.

Input and output๐Ÿ”—

lists.range(int) -> list

Generates a list of integers from 0 (inclusive) to n (exclusive).

Returns [0, 1, 2, ..., n-1].

Returns an empty list for values less than or equal to 0.

Use cases๐Ÿ”—

Generate index list.

lists.range(items.size())

Get indices for a list.

Iterate N times.

lists.range(5).map(i, processItem(i))

Execute a function five times with an index.

Create test data.

lists.range(100)

Generate 100 sequential numbers.

Batch processing.

lists.range(totalItems / batchSize).map(i, processBatch(i))

Process items in batches.

Pagination.

lists.range(totalPages)

Generate page numbers.

Fill an array.

lists.range(10).map(i, 'item-' + string(i))

Output: ['item-0', 'item-1', ..., 'item-9']

Create a list of strings.

lowerAscii๐Ÿ”—

Converts all ASCII characters in the string to lowercase.

Input and output๐Ÿ”—

string.lowerAscii() -> string

Converts all ASCII uppercase letters (A-Z) to lowercase (a-z).

Non-ASCII characters are left unchanged.

Examples๐Ÿ”—

'HELLO World'.lowerAscii()

'HELLO World'.lowerAscii()

Output: "hello world"

'ABC123XYZ'.lowerAscii()

'ABC123XYZ'.lowerAscii()

Output: "abc123xyz"

'Cafรฉ'.lowerAscii()

'Cafรฉ'.lowerAscii()

Output: "cafรฉ"

map๐Ÿ”—

Converts input to a map.

Input and output๐Ÿ”—

map(list) -> map

Examples๐Ÿ”—

map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))

map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))

Output: {"1": {"a": 1, "b": 2}, "3": {"a": 3, "b": 4}}

matchGroup๐Ÿ”—

Returns a list of strings from the provided regex capture group or groups.

Input and output๐Ÿ”—

matchGroup(string, string) -> list

Examples๐Ÿ”—

"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")

"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")

Output: ["https://www.example.com", "https://", "www.example.com"]

math.abs๐Ÿ”—

Returns the absolute value of a number.

Input and output๐Ÿ”—

math.abs(double) -> double
math.abs(int) -> int
math.abs(uint) -> uint

Returns the absolute (non-negative) value of the input number.

Works with int, uint, and double types.

Examples๐Ÿ”—

math.abs(-5)

math.abs(-5)

Output: 5

math.abs(5)

math.abs(5)

Output: 5

math.abs(-3.14)

math.abs(-3.14)

Output: 3.14

math.abs(0)

math.abs(0)

Output: 0

math.bitAnd๐Ÿ”—

Performs a bitwise AND operation on two integers.

Input and output๐Ÿ”—

math.bitAnd(int, int) -> int
math.bitAnd(uint, uint) -> uint

Returns the bitwise AND of two integers.

Each bit in the result is 1 only if both corresponding bits in the operands are 1.

Examples๐Ÿ”—

math.bitAnd(5, 3)

math.bitAnd(5, 3)

Output: 1 (0101 & 0011 = 0001)

math.bitAnd(12, 10)

math.bitAnd(12, 10)

Output: 8 (1100 & 1010 = 1000)

math.bitAnd(15, 15)

math.bitAnd(15, 15)

Output: 15

math.bitAnd(7, 0)

math.bitAnd(7, 0)

Output: 0

math.bitNot๐Ÿ”—

Performs a bitwise NOT (complement) operation on an integer.

Input and output๐Ÿ”—

math.bitNot(int) -> int
math.bitNot(uint) -> uint

Returns the bitwise complement of the integer.

Each bit is flipped: 0 becomes 1, and 1 becomes 0.

Examples๐Ÿ”—

math.bitNot(0)

math.bitNot(0)

Output: -1

math.bitNot(-1)

math.bitNot(-1)

Output: 0

math.bitNot(5)

math.bitNot(5)

Output: -6

math.bitNot(10)

math.bitNot(10)

Output: -11

math.bitOr๐Ÿ”—

Performs a bitwise OR operation on two integers.

Input and output๐Ÿ”—

math.bitOr(int, int) -> int
math.bitOr(uint, uint) -> uint

Returns the bitwise OR of two integers.

Each bit in the result is 1 if either corresponding bit in the operands is 1.

Examples๐Ÿ”—

math.bitOr(5, 3)

math.bitOr(5, 3)

Output: 7 (0101 0011 = 0111)

math.bitOr(8, 4)

math.bitOr(8, 4)

Output: 12 (1000 0100 = 1100)

math.bitOr(0, 15)

math.bitOr(0, 15)

Output: 15

math.bitOr(7, 0)

math.bitOr(7, 0)

Output: 7

math.bitShiftLeft๐Ÿ”—

Shifts the bits of an integer to the left by the specified number of positions.

Input and output๐Ÿ”—

math.bitShiftLeft(int, int) -> int
math.bitShiftLeft(uint, uint) -> uint

Shifts all bits to the left by the specified number of positions.

Zeros are shifted in from the right. This is equivalent to multiplying by 2^n.

Examples๐Ÿ”—

math.bitShiftLeft(5, 1)

math.bitShiftLeft(5, 1)

Output: 10 (0101 << 1 = 1010)

math.bitShiftLeft(5, 2)

math.bitShiftLeft(5, 2)

Output: 20 (0101 << 2 = 10100)

math.bitShiftLeft(1, 3)

math.bitShiftLeft(1, 3)

Output: 8

math.bitShiftLeft(3, 4)

math.bitShiftLeft(3, 4)

Output: 48

math.bitShiftRight๐Ÿ”—

Shifts the bits of an integer to the right by the specified number of positions.

Input and output๐Ÿ”—

math.bitShiftRight(int, int) -> int
math.bitShiftRight(uint, uint) -> uint

Shifts all bits to the right by the specified number of positions.

For unsigned integers, zeros are shifted in from the left.

For signed integers, the sign bit is preserved. This is equivalent to dividing by 2^n.

Examples๐Ÿ”—

math.bitShiftRight(10, 1)

math.bitShiftRight(10, 1)

Output: 5 (1010 >> 1 = 0101)

math.bitShiftRight(20, 2)

math.bitShiftRight(20, 2)

Output: 5 (10100 >> 2 = 0101)

math.bitShiftRight(8, 3)

math.bitShiftRight(8, 3)

Output: 1

math.bitShiftRight(48, 4)

math.bitShiftRight(48, 4)

Output: 3

math.bitXor๐Ÿ”—

Performs a bitwise XOR (exclusive OR) operation on two integers.

Input and output๐Ÿ”—

math.bitXor(int, int) -> int
math.bitXor(uint, uint) -> uint

Returns the bitwise XOR of two integers.

Each bit in the result is 1 if the corresponding bits in the operands are different.

Examples๐Ÿ”—

math.bitXor(5, 3)

math.bitXor(5, 3)

Output: 6 (0101 ^ 0011 = 0110)

math.bitXor(12, 10)

math.bitXor(12, 10)

Output: 6 (1100 ^ 1010 = 0110)

math.bitXor(15, 15)

math.bitXor(15, 15)

Output: 0

math.bitXor(7, 0)

math.bitXor(7, 0)

Output: 7

math.ceil๐Ÿ”—

Rounds a number up to the nearest integer (towards positive infinity).

Input and output๐Ÿ”—

math.ceil(double) -> double

Returns the smallest integer value greater than or equal to the input.

Always rounds up, even for negative numbers.

Examples๐Ÿ”—

math.ceil(1.2)

math.ceil(1.2)

Output: 2.0

math.ceil(1.9)

math.ceil(1.9)

Output: 2.0

math.ceil(-1.2)

math.ceil(-1.2)

Output: -1.0

math.ceil(5.0)

math.ceil(5.0)

Output: 5.0

math.floor๐Ÿ”—

Rounds a number down to the nearest integer (towards negative infinity).

Input and output๐Ÿ”—

math.floor(double) -> double

Returns the largest integer value less than or equal to the input.

Always rounds down, even for negative numbers.

Examples๐Ÿ”—

math.floor(1.2)

math.floor(1.2)

Output: 1.0

math.floor(1.9)

math.floor(1.9)

Output: 1.0

math.floor(-1.2)

math.floor(-1.2)

Output: -2.0

math.floor(5.0)

math.floor(5.0)

Output: 5.0

math.greatest๐Ÿ”—

Returns the maximum value from the provided arguments.

Input and output๐Ÿ”—

math.greatest(...) -> number

Returns the largest value among all provided arguments.

Accepts a variable number of arguments (int, uint, or double).

All arguments must be of comparable numeric types.

Examples๐Ÿ”—

math.greatest(1, 5, 3, 9, 2)

math.greatest(1, 5, 3, 9, 2)

Output: 9

math.greatest(-10, -5, -20)

math.greatest(-10, -5, -20)

Output: -5

math.greatest(1.5, 2.3, 0.9)

math.greatest(1.5, 2.3, 0.9)

Output: 2.3

math.greatest(42)

math.greatest(42)

Output: 42

math.isFinite๐Ÿ”—

Checks if a value is a finite number (not NaN or infinity).

Input and output๐Ÿ”—

math.isFinite(double) -> bool

Returns true if the value is a finite number (not NaN or infinity).

Returns false for NaN, positive infinity, or negative infinity.

Examples๐Ÿ”—

math.isFinite(3.14)

math.isFinite(3.14)

Output: true

math.isFinite(1.0 / 0.0)

math.isFinite(1.0 / 0.0)

Output: false

math.isFinite(0.0 / 0.0)

math.isFinite(0.0 / 0.0)

Output: false

math.isFinite(-100.5)

math.isFinite(-100.5)

Output: true

math.isInf๐Ÿ”—

Checks if a value is positive or negative infinity.

Input and output๐Ÿ”—

math.isInf(double) -> bool

Returns true if the value is infinity.

Examples๐Ÿ”—

math.isInf(1.0 / 0.0)

math.isInf(1.0 / 0.0)

Output: true

math.isInf(-1.0 / 0.0)

math.isInf(-1.0 / 0.0)

Output: true

math.isInf(1.0 / 0.0)

math.isInf(1.0 / 0.0)

Output: true

math.isInf(3.14)

math.isInf(3.14)

Output: false

math.isNaN๐Ÿ”—

Checks if a value is NaN (Not a Number).

Input and output๐Ÿ”—

math.isNaN(double) -> bool

Returns true if the value is NaN. Otherwise, returns false.

Only applies to floating-point values.

Examples๐Ÿ”—

math.isNaN(0.0 / 0.0)

math.isNaN(0.0 / 0.0)

Output: true

math.isNaN(1.0)

math.isNaN(1.0)

Output: false

math.isNaN(math.sqrt(-1.0))

math.isNaN(math.sqrt(-1.0))

Output: true

math.isNaN(3.14)

math.isNaN(3.14)

Output: false

math.least๐Ÿ”—

Returns the minimum value from the provided arguments.

Input and output๐Ÿ”—

math.least(...) -> number

Returns the smallest value among all provided arguments.

Accepts a variable number of arguments (int, uint, or double).

All arguments must be of comparable numeric types.

Examples๐Ÿ”—

math.least(1, 5, 3, 9, 2)

math.least(1, 5, 3, 9, 2)

Output: 1

math.least(-10, -5, -20)

math.least(-10, -5, -20)

Output: -20

math.least(1.5, 2.3, 0.9)

math.least(1.5, 2.3, 0.9)

Output: 0.9

math.least(42)

math.least(42)

Output: 42

math.round๐Ÿ”—

Rounds a number to the nearest integer (half away from zero).

Input and output๐Ÿ”—

math.round(double) -> double

Returns the nearest integer value, rounding half values away from zero.

For positive numbers, 0.5 rounds up. For negative numbers, -0.5 rounds down.

Examples๐Ÿ”—

math.round(1.4)

math.round(1.4)

Output: 1.0

math.round(1.5)

math.round(1.5)

Output: 2.0

math.round(-1.5)

math.round(-1.5)

Output: -2.0

math.round(5.0)

math.round(5.0)

Output: 5.0

math.sign๐Ÿ”—

Returns the sign of a number: -1 for negative, 0 for zero, and 1 for positive.

Input and output๐Ÿ”—

math.sign(double) -> double
math.sign(int) -> int

Returns:

  • -1 if the number is negative.
  • 0 if the number is zero.
  • 1 if the number is positive.

Examples๐Ÿ”—

math.sign(-5)

math.sign(-5)

Output: -1

math.sign(0)

math.sign(0)

Output: 0

math.sign(5)

math.sign(5)

Output: 1

math.sign(-3.14)

math.sign(-3.14)

Output: -1.0

math.sqrt๐Ÿ”—

Returns the square root of a number.

Input and output๐Ÿ”—

math.sqrt(int) -> double
math.sqrt(double) -> double

Returns the square root of the input number.

Returns NaN for negative inputs.

Examples๐Ÿ”—

math.sqrt(9.0)

math.sqrt(9.0)

Output: 3.0

math.sqrt(16)

math.sqrt(16)

Output: 4.0

math.sqrt(2.0)

math.sqrt(2.0)

Output: 1.414...

math.sqrt(0.0)

math.sqrt(0.0)

Output: 0.0

math.trunc๐Ÿ”—

Truncates a number to its integer part (towards zero).

Input and output๐Ÿ”—

math.trunc(double) -> double

Returns the integer part of the number by removing the fractional part.

Rounds towards zero for both positive and negative numbers.

Examples๐Ÿ”—

math.trunc(1.9)

math.trunc(1.9)

Output: 1.0

math.trunc(-1.9)

math.trunc(-1.9)

Output: -1.0

math.trunc(5.0)

math.trunc(5.0)

Output: 5.0

math.trunc(3.14159)

math.trunc(3.14159)

Output: 3.0

md5sum๐Ÿ”—

Returns the computed MD5 digest for the provided string.

Input and output๐Ÿ”—

md5sum(string) -> bytes

Examples๐Ÿ”—

md5sum("Hello").toHex()

md5sum("Hello").toHex()

Output: "8b1a9953c4611296a827abf8c47804d7"

merge๐Ÿ”—

Adds elements to an existing map.

Input and output๐Ÿ”—

merge(map, map) -> map

Examples๐Ÿ”—

merge({"key1": "val1"}, {"key2": "val2"})

merge({"key1": "val1"}, {"key2": "val2"})

Output: {"key1": "val1", "key2": "val2"}

now๐Ÿ”—

Returns the current local time as a timestamp.

Input and output๐Ÿ”—

now() -> timestamp

Examples๐Ÿ”—

now()

now()

Output: "2025-04-29T12:34:56.789Z"

nowUnixMilli๐Ÿ”—

Returns the current time as the number of milliseconds since epoch.

Input and output๐Ÿ”—

nowUnixMilli() -> int

Examples๐Ÿ”—

nowUnixMilli()

nowUnixMilli()

Output: 1742395914211

optFlatMap๐Ÿ”—

Transforms the optional's value with a function that returns an optional, flattening the result.

Input and output๐Ÿ”—

optional(T).optFlatMap(var, expr) -> optional(R)

Applies a transformation that returns an optional.

Unlike optMap, this doesn't nest optionals. If the original optional is empty or the transformation returns optional.none(), the result is optional.none().

Use cases๐Ÿ”—

Chained optional access.

optional.of([1, 2, 3]).optFlatMap(l, l[?0])

Get the first element as an optional.

Conditional transformation.

optional.of(value).optFlatMap(v, v > 0 ? optional.of(v * 2) : optional.none())

Transform only if the condition is met.

Safe nested access.

optional.of(user).optFlatMap(u, u.?email)

Access a nested optional value safely.

Zero-value filtering.

optional.of(input).optFlatMap(i, optional.ofNonZeroValue(i.trim()))

Filter empty strings after trimming.

Multiple optional sources.

optional.of(config).optFlatMap(c, c[?'setting'])

Perform an optional map lookup within an optional object.

Notes๐Ÿ”—

  • Variable binding syntax: optFlatMap(var, expression returning optional).
  • Prevents nested optionals such as optional(optional(T)).
  • Useful when the transformation itself returns an optional.
  • Empty optionals pass through unchanged as optional.none().
  • The transformation only runs when the optional contains a value.

Examples๐Ÿ”—

optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)

optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)

Output: 1

optional.of([]).optFlatMap(l, l[?0]).orValue(0)

optional.of([]).optFlatMap(l, l[?0]).orValue(0)

Output: 0

optional.none().optFlatMap(l, l[?0]).orValue(0)

optional.none().optFlatMap(l, l[?0]).orValue(0)

Output: 0

optMap๐Ÿ”—

Transforms the optional's value if present, returning a new optional with the transformed value.

Input and output๐Ÿ”—

optional(T).optMap(var, expr) -> optional(R)

Applies a transformation to the optional's value if present.

The transformation returns a new value that is wrapped in an optional.

If the optional is empty, returns optional.none().

Use cases๐Ÿ”—

Transform a value.

optional.of(5).optMap(x, x * 2)

Output: optional(10)

Double the value.

String manipulation.

optional.of('hello').optMap(s, s.upperAscii())

Output: optional('HELLO')

Transform to uppercase.

Property access.

optional.of(user).optMap(u, u.email)

Extract a property from a wrapped object.

Complex calculation.

optional.of([1, 2, 3]).optMap(l, l.size())

Output: optional(3)

Get the size of a list.

Chained transformations.

optional.of(10).optMap(x, x * 2).optMap(x, x + 1).orValue(0)

Output: 21

Chain multiple transformations.

Filter with map.

optional.of([1, 2, 3, 4, 5]).optMap(l, l.filter(x, x > 2))

Transform and filter data.

Safe navigation.

data.?user.optMap(u, u.name).orValue('Anonymous')

Safe nested access with transformation.

Notes๐Ÿ”—

  • Variable binding syntax: optMap(var, expression using var).
  • Returns optional(R) where R is the result type.
  • Empty optionals pass through unchanged.
  • Use .orValue() to extract the final result.
  • Compare with .optFlatMap() when the transformation returns an optional.

Examples๐Ÿ”—

optional.of(5).optMap(x, x * 2).orValue(0)

optional.of(5).optMap(x, x * 2).orValue(0)

Output: 10

optional.none().optMap(x, x * 2).orValue(0)

optional.none().optMap(x, x * 2).orValue(0)

Output: 0

optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')

optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')

Output: 'HELLO'

optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)

optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)

Output: 3

optional.none๐Ÿ”—

Creates an empty optional value with no content.

Input and output๐Ÿ”—

optional.none() -> optional

Creates an empty optional value that contains no value.

Use cases๐Ÿ”—

Represent a missing value.

optional.none()

Explicit absence of a value.

Use as a default in a conditional.

hasError ? optional.none() : optional.of(result)

Return an empty optional when an error occurs.

Chain with .or().

optional.none().or(optional.of(5))

Fall back to another optional.

Check emptiness.

optional.none().hasValue()

Output: false

Check whether an optional is empty.

Provide a default.

optional.none().orValue('default')

Extract a value with a fallback.

Notes๐Ÿ”—

  • Represents the absence of a value (similar to null).
  • .hasValue() returns false for optional.none().
  • Calling .value() on optional.none() causes an error.
  • Use .orValue() to provide a default value.
  • Use .or() to chain with other optionals.

Examples๐Ÿ”—

optional.none().hasValue()

optional.none().hasValue()

Output: false

optional.none().orValue(42)

optional.none().orValue(42)

Output: 42

optional.none().or(optional.of(5)).orValue(0)

optional.none().or(optional.of(5)).orValue(0)

Output: 5

optional.of๐Ÿ”—

Creates an optional value containing the given value.

Input and output๐Ÿ”—

optional.of(T) -> optional(T)

Creates an optional value that contains the given value.

Any value is considered valid, including zero values.

Use cases๐Ÿ”—

Wrap a known value.

optional.of(42)

Create an optional containing 42.

Wrap zero or empty values.

optional.of(0)

Create an optional containing 0.

Wrap an empty string.

optional.of('')

Create an optional containing an empty string.

Chain transformations.

optional.of(5).optMap(x, x * 2)

Transform the wrapped value.

Conditional wrapping.

hasValue ? optional.of(value) : optional.none()

Wrap a value conditionally.

Default value pattern.

optional.of(userInput).orValue('default')

Wrap input with a fallback.

Notes๐Ÿ”—

  • Accepts any value, including zero values such as 0, '', [], or {}.
  • Returns optional(T) where T is the value type.
  • Compare with optional.ofNonZeroValue(), which rejects zero values.
  • Use .hasValue() to check whether a value exists.
  • Use .orValue() to extract a value with a fallback.

Examples๐Ÿ”—

optional.of(42)

optional.of(42)

Output: optional(42)

optional.of('hello')

optional.of('hello')

Output: optional('hello')

optional.of([1, 2, 3])

optional.of([1, 2, 3])

Output: optional([1, 2, 3])

optional.of(0).hasValue()

optional.of(0).hasValue()

Output: true

optional.ofNonZeroValue๐Ÿ”—

Creates an optional containing the value only if it's non-zero. Otherwise, returns optional.none().

Input and output๐Ÿ”—

optional.ofNonZeroValue(T) -> optional(T)

Creates an optional containing the given value only if it's not a zero or empty value.

Zero values such as 0, '', [], {}, and null result in optional.none().

Use cases๐Ÿ”—

Filter zero values.

optional.ofNonZeroValue(userInput)

Only wrap non-empty input.

Validate non-empty values.

optional.ofNonZeroValue('').hasValue()

Output: false

Check whether a string is non-empty.

Skip empty lists.

optional.ofNonZeroValue([]).orValue([1, 2, 3])

Use a default value for an empty list.

Conditional processing.

optional.ofNonZeroValue(score).optMap(s, s * 100)

Only process non-zero scores.

Null safety.

optional.ofNonZeroValue(null).orValue('N/A')

Handle null values safely.

Notes๐Ÿ”—

Zero values by type:

  • Numeric: 0, 0.0
  • String: ''
  • List: []
  • Map: {}
  • Boolean: false
  • Bytes: b''
  • Null: null

Additional notes:

  • Returns optional.none() for zero values.
  • Use when you want to treat empty or zero values as absent.
  • Compare with optional.of(), which accepts all values.
  • Useful for validation and filtering.

Examples๐Ÿ”—

optional.ofNonZeroValue(42).hasValue()

optional.ofNonZeroValue(42).hasValue()

Output: true

Non-zero numeric value.

optional.ofNonZeroValue(0).hasValue()

optional.ofNonZeroValue(0).hasValue()

Output: false

Zero is rejected.

optional.ofNonZeroValue('').hasValue()

optional.ofNonZeroValue('').hasValue()

Output: false

Empty string is rejected.

optional.ofNonZeroValue('hello').hasValue()

optional.ofNonZeroValue('hello').hasValue()

Output: true

Non-empty string is accepted.

or๐Ÿ”—

Returns the first optional if it has a value. Otherwise, returns the second optional.

Input and output๐Ÿ”—

optional(T).or(optional(T)) -> optional(T)

Chains optional values.

If the left optional has a value, it is returned. Otherwise, the right optional is returned.

Evaluation is short-circuited.

Use cases๐Ÿ”—

Fallback chain.

optional.none().or(optional.of(5))

Use an alternative optional value.

Multiple sources.

cache[?key].or(database[?key]).or(optional.of(default))

Try cache, then database, then a default value.

Coalesce pattern.

primary.or(secondary).or(tertiary).orValue(fallback)

Chain multiple optional sources.

Safe navigation chain.

obj.?field1.or(obj.?field2).orValue('none')

Try multiple fields in priority order.

Priority-based selection.

premium.?feature.or(basic.?feature)

Prefer a premium feature and fall back to a basic feature.

Notes๐Ÿ”—

  • Returns optional(T), not T.
  • Use .orValue() at the end to extract the final value.
  • Short-circuits evaluation when the first optional has a value.
  • Useful for chaining multiple optional sources.
  • Compare with .orValue(), which returns a concrete value.

Examples๐Ÿ”—

optional.none().or(optional.of(5)).orValue(0)

optional.none().or(optional.of(5)).orValue(0)

Output: 5

optional.of(3).or(optional.of(5)).orValue(0)

optional.of(3).or(optional.of(5)).orValue(0)

Output: 3

optional.none().or(optional.none()).orValue(10)

optional.none().or(optional.none()).orValue(10)

Output: 10

orValue๐Ÿ”—

Returns the value from the optional if present. Otherwise, returns the provided default value.

Input and output๐Ÿ”—

optional(T).orValue(T) -> T

Extracts the value from an optional if present, otherwise returns the provided default value.

Use cases๐Ÿ”—

Provide a default.

optional.none().orValue(42)

Output: 42

Use a default when the optional is empty.

Safe field access.

obj.?field.orValue('N/A')

Get a field value or return a default.

Safe map access.

config[?'timeout'].orValue(30)

Get a configuration value with a fallback.

Safe list access.

items[?0].orValue('empty')

Get the first item or return a default.

Chain operations.

optional.of(5).orValue(0) * 2

Output: 10

Use the extracted value directly in a calculation.

Nested access.

data.?user.?name.orValue('Anonymous')

Safely access nested fields.

Coalesce pattern.

primary.orValue(secondary.orValue(tertiary))

Chain multiple fallback values.

Notes๐Ÿ”—

  • The default value must match the optional type.
  • Always returns a concrete value.
  • Safe to use anywhere a normal value is expected.
  • More concise than conditional expressions.
  • Compare with .value(), which throws an error for empty optionals.

Examples๐Ÿ”—

optional.of(42).orValue(0)

optional.of(42).orValue(0)

Output: 42

optional.none().orValue(0)

optional.none().orValue(0)

Output: 0

optional.of('hello').orValue('default')

optional.of('hello').orValue('default')

Output: 'hello'

{'a': 1}[?'b'].orValue(0)

{'a': 1}[?'b'].orValue(0)

Output: 0

parseURL๐Ÿ”—

Returns the provided URL string as a URL map structure.

Input and output๐Ÿ”—

parseURL(string) -> map

Examples๐Ÿ”—

parseURL("https://www.example.com")

parseURL("https://www.example.com")

Output: {"Scheme": "https", "Host": "www.example.com", "Path": "", "RawQuery": "", "Fragment": ""}

queryJSON๐Ÿ”—

Returns data from the first argument using the JMESPath query provided in the second argument.

Input and output๐Ÿ”—

queryJSON(map, string) -> any

Examples๐Ÿ”—

queryJSON(inputs.alert2, "metadata.confidence")

queryJSON(inputs.alert2, "metadata.confidence")

Output: 0.5

random๐Ÿ”—

Returns a random value between 0 and .99 (inclusive).

Input and output๐Ÿ”—

random() -> double

Examples๐Ÿ”—

random()

random()

Output: 0.42

regex.extract๐Ÿ”—

Extracts the first match of a regular expression pattern from a string, returning an optional value.

Input and output๐Ÿ”—

regex.extract(string, pattern) -> string

Applies a regular expression pattern to a string and returns the first match wrapped in an optional.

If the pattern contains a capturing group, the captured value is returned.

If the pattern contains no capturing groups, the entire match is returned.

Returns optional.none() if no match is found.

Notes๐Ÿ”—

Pattern syntax:

  • Uses RE2 regular expression syntax.
  • Capturing groups use parentheses ().
  • Backslashes must be escaped in CEL strings.
  • Common patterns include \d, \w, and \s.

Additional notes:

  • Returns an optional value. Use .orValue() or .hasValue().
  • Pattern matching proceeds left-to-right and returns only the first match.
  • Use extractAll() to retrieve all matches.
  • Empty strings and empty patterns are handled gracefully.
  • Invalid regex patterns cause compilation errors.

regex.extractAll๐Ÿ”—

Extracts all matches of a regular expression pattern from a string as a list.

Input and output๐Ÿ”—

regex.extractAll(string, pattern) -> list

Applies a regular expression pattern to a string and returns all matches as a list of strings.

Returns an empty list if no matches are found.

Unlike extract(), this function returns all matches, not just the first one.

Use cases๐Ÿ”—

Extract all numbers.

regex.extractAll('test123foo456bar', '\\d+')

Output: ["123", "456"]

Find all numeric sequences.

Extract all words.

regex.extractAll('hello world test', '\\w+')

Output: ["hello", "world", "test"]

Split text into words.

Parse multiple values.

regex.extractAll('192.168.1.1', '\\d+')

Output: ["192", "168", "1", "1"]

Extract all numeric values from an IP address.

Find all email addresses.

regex.extractAll(text, '\\w+@\\w+\\.\\w+')

Extract all email addresses from a string.

Count matches.

regex.extractAll('test123foo456bar', '\\d+').size()

Output: 2

Count the number of numeric sequences.

Check for matches.

regex.extractAll('no-numbers-here', '\\d+').size() == 0

Output: true

Check whether the pattern matches anything.

Extract and process.

regex.extractAll('1,2,3,4,5', '\\d+').map(x, int(x))

Output: [1, 2, 3, 4, 5]

Extract numbers and convert them to integers.

Filter results.

regex.extractAll('a1 b2 c3', '\\w+').filter(x, x.size() > 1)

Output: ["a1", "b2", "c3"]

Extract tokens and filter by length.

Notes๐Ÿ”—

  • Returns a list instead of an optional value.
  • Returns an empty list when no matches are found.
  • Capturing groups are ignored. Only full matches are returned.
  • Useful for extracting multiple values from a string.
  • More efficient than multiple calls to extract().
  • Preserves left-to-right match order.

Examples๐Ÿ”—

regex.extractAll('test123foo456bar', '\\d+')

regex.extractAll('test123foo456bar', '\\d+')

Output: ["123", "456"]

regex.extractAll('hello world test', '\\w+')

regex.extractAll('hello world test', '\\w+')

Output: ["hello", "world", "test"]

regex.extractAll('192.168.1.1', '\\d+')

regex.extractAll('192.168.1.1', '\\d+')

Output: ["192", "168", "1", "1"]

regex.extractAll('no-numbers-here', '\\d+')

regex.extractAll('no-numbers-here', '\\d+')

Output: []

regex.replace๐Ÿ”—

Replaces occurrences of a regular expression pattern in a string with a replacement string.

Input and output๐Ÿ”—

regex.replace(string, pattern, replacement) -> string
regex.replace(string, pattern, replacement, count) -> string

Replaces non-overlapping substrings matching the regex pattern.

Optionally limits the number of replacements using the count argument.

When count is omitted or negative, all occurrences are replaced.

Use cases๐Ÿ”—

Simple text replacement.

regex.replace('hello world hello', 'hello', 'hi')

Output: "hi world hi"

Replace all occurrences of hello.

Remove all digits.

regex.replace('test123test456', '\\d+', '')

Output: "testtest"

Remove all numeric sequences.

Mask sensitive data.

regex.replace('ID: 12345', '\\d+', 'XXXXX')

Output: "ID: XXXXX"

Replace numbers with a placeholder.

Limited replacements.

regex.replace('banana', 'a', 'x', 1)

Output: "bxnana"

Replace only the first occurrence.

Replace all with negative count.

regex.replace('banana', 'a', 'x', -1)

Output: "bxnxnx"

Negative count means replace all occurrences.

Normalize whitespace.

regex.replace('hello world test', '\\s+', ' ')

Output: "hello world test"

Replace multiple spaces with a single space.

Clean special characters.

regex.replace('hello@world#test', '[^a-zA-Z0-9]', '')

Output: "helloworldtest"

Remove non-alphanumeric characters.

Format phone numbers.

regex.replace('1234567890', '(\\d{3})(\\d{3})(\\d{4})', '($1) $2-$3')

Format a phone number using capture groups.

Notes๐Ÿ”—

  • Pattern must be a valid regular expression.
  • Replacement string is treated literally except for capture-group references.
  • When count is 0, the original string is returned unchanged.
  • When count is negative, all matches are replaced.
  • Non-matching patterns return the original string unchanged.
  • Empty patterns match between characters.

Capture group references:

  • Use \1, \2, \3, and so on.
  • Only numeric capture groups are supported.
  • Named capture groups aren't supported in replacement strings.
  • Invalid capture-group references cause runtime errors.

Examples๐Ÿ”—

regex.replace('hello world hello', 'hello', 'hi')

regex.replace('hello world hello', 'hello', 'hi')

Output: "hi world hi"

regex.replace('banana', 'a', 'x')

regex.replace('banana', 'a', 'x')

Output: "bxnxnx"

regex.replace('test123test456', '\\d+', 'NUM')

regex.replace('test123test456', '\\d+', 'NUM')

Output: "testNUMtestNUM"

regex.replace('banana', 'a', 'x', 1)

regex.replace('banana', 'a', 'x', 1)

Output: "bxnana"

regex.replace('foo bar', 'foo', 'hello')

regex.replace('foo bar', 'hello')

Output: "hello bar"

replace๐Ÿ”—

Replaces all occurrences of a substring with another string.

Input and output๐Ÿ”—

string.replace(string, string) -> string
string.replace(string, string, int) -> string

Replaces occurrences of the first substring with the second substring.

An optional third argument limits the number of replacements. Use -1 to replace all occurrences.

Examples๐Ÿ”—

'hello world'.replace('o', 'a')

'hello world'.replace('o', 'a')

Output: "hella warld"

'hello world'.replace('l', 'L')

'hello world'.replace('l', 'L')

Output: "heLLo worLd"

'hello world'.replace('l', 'L', 1)

'hello world'.replace('l', 'L', 1)

Output: "heLlo world"

'hello world'.replace('world', 'universe')

'hello world'.replace('world', 'universe')

Output: "hello universe"

resolvePartnerName๐Ÿ”—

Resolves a Taegis tenant ID and returns the partner name.

Input and output๐Ÿ”—

resolvePartnerName(string) -> string

Examples๐Ÿ”—

resolvePartnerName('12345')

resolvePartnerName('12345')

Output: "Partner Name"

resolveSubjectName๐Ÿ”—

Resolves a Taegis user ID or client ID and returns a name string.

Input and output๐Ÿ”—

resolveSubjectName(string) -> string

Examples๐Ÿ”—

resolveSubjectName('auth0asdf')

resolveSubjectName('auth0asdf')

Output: "GivenName FamilyName"

resolveSubjectName('ff0197b0@clients')

resolveSubjectName('ff0197b0@clients')

Output: "ClientName"

resolveTenantName๐Ÿ”—

Resolves a Taegis tenant ID and returns the tenant name.

Input and output๐Ÿ”—

resolveTenantName(string) -> string

Examples๐Ÿ”—

resolveTenantName('12345')

resolveTenantName('12345')

Output: "Tenant Name"

resolveUser๐Ÿ”—

Resolves a Taegis user by ID, Auth0 ID, or email address and returns the Taegis user ID.

Input and output๐Ÿ”—

resolveUser(string) -> string

Examples๐Ÿ”—

resolveUser('auth0asdf')

resolveUser('auth0asdf')

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

resolveUserName๐Ÿ”—

Resolves a Taegis user ID and returns the username string.

Input and output๐Ÿ”—

resolveUserName(string) -> string

Examples๐Ÿ”—

resolveUserName('auth0asdf')

resolveUserName('auth0asdf')

Output: "GivenName FamilyName"

reverse๐Ÿ”—

Reverses the order of elements in a list.

Input and output๐Ÿ”—

list.reverse() -> list

Returns a new list with elements in reverse order.

The first element becomes the last, and vice versa.

Does not modify the original list.

Use cases๐Ÿ”—

Reverse chronological order.

events.reverse()

Show the most recent events first.

Process in reverse.

steps.reverse().map(s, s.execute())

Execute steps in reverse order.

Palindrome check.

list == list.reverse()

Check whether a list is a palindrome.

Last-to-first processing.

queue.reverse()

Process items in LIFO order.

Reverse and filter.

items.reverse().filter(i, i.priority > 5)

Reverse the list and then filter it.

Reverse twice.

list.reverse().reverse() == list

Output: true

Double reversing returns the original list.

Notes๐Ÿ”—

  • Returns a new list.
  • Works with any list type.
  • Empty and single-element lists are unchanged.
  • Reversing twice returns the original order.

Examples๐Ÿ”—

[1, 2, 3, 4].reverse()

[1, 2, 3, 4].reverse()

Output: [4, 3, 2, 1]

['a', 'b', 'c'].reverse()

['a', 'b', 'c'].reverse()

Output: ['c', 'b', 'a']

[1].reverse()

[1].reverse()

Output: [1]

[].reverse()

[].reverse()

Output: []

[5, 3, 1, 2].reverse()

[5, 3, 1, 2].reverse()

Output: [2, 1, 3, 5]

sets.contains๐Ÿ”—

Checks whether the first list contains all elements from the second list (subset check).

Input and output๐Ÿ”—

sets.contains(list, list) -> bool

Returns true if the first list contains all elements from the second list.

The first list is considered a superset of the second list.

Order doesn't matter.

Duplicates in either list are ignored.

Use cases๐Ÿ”—

Permission checking.

sets.contains(user.roles, ['admin'])

Check whether a user has the required role.

Required tags validation.

sets.contains(resource.tags, ['production', 'critical'])

Validate that a resource contains all required tags.

Feature availability.

sets.contains(subscription.features, ['api_access', 'export'])

Check whether a subscription includes all required features.

Empty list handling.

sets.contains([1, 2, 3], [])

Output: true

An empty list is a subset of any list.

Duplicate handling.

sets.contains([1, 1, 2, 2, 3], [1, 2])

Output: true

Duplicates are ignored.

Examples๐Ÿ”—

sets.contains([1, 2, 3, 4], [2, 3])

sets.contains([1, 2, 3, 4], [2, 3])

Output: true

sets.contains([1, 2, 3], [3, 2, 1])

sets.contains([1, 2, 3], [3, 2, 1])

Output: true

sets.contains([1, 2, 3], [1, 2, 4])

sets.contains([1, 2, 3], [1, 2, 4])

Output: false

sets.contains(['admin', 'user', 'guest'], ['admin'])

sets.contains(['admin', 'user', 'guest'], ['admin'])

Output: true

sets.equivalent๐Ÿ”—

Checks whether two lists contain the same elements, ignoring order and duplicates (set equality).

Input and output๐Ÿ”—

sets.equivalent(list, list) -> bool

Returns true if both lists contain exactly the same elements.

Order doesn't matter.

Duplicates are ignored.

Use cases๐Ÿ”—

Compare user permissions.

sets.equivalent(user1.permissions, user2.permissions)

Check whether two users have identical permissions.

Tag comparison.

sets.equivalent(resource1.tags, resource2.tags)

Compare resource tags.

Validate configuration.

sets.equivalent(actual_settings, expected_settings)

Verify that configuration values match.

Empty lists.

sets.equivalent([], [])

Output: true

Empty lists are equivalent.

String comparison.

sets.equivalent(['a', 'b', 'c'], ['c', 'a', 'b'])

Output: true

Works with any comparable type.

Symmetric operation.

sets.equivalent(list1, list2) == sets.equivalent(list2, list1)

Output: true

Argument order doesn't matter.

Examples๐Ÿ”—

sets.equivalent([1, 2, 3], [3, 2, 1])

sets.equivalent([1, 2, 3], [3, 2, 1])

Output: true

sets.equivalent([1, 2, 3], [1, 2, 3])

sets.equivalent([1, 2, 3], [1, 2, 3])

Output: true

sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])

sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])

Output: true

sets.equivalent([1, 2, 3], [1, 2, 4])

sets.equivalent([1, 2, 3], [1, 2, 4])

Output: false

sets.intersects๐Ÿ”—

Checks whether two lists have any common elements (non-empty intersection).

Input and output๐Ÿ”—

sets.intersects(list, list) -> bool

Returns true if the two lists share at least one common element.

Order doesn't matter.

Duplicates are ignored.

Use cases๐Ÿ”—

Role-based access control.

sets.intersects(user.roles, ['admin', 'owner', 'moderator'])

Check whether a user has at least one privileged role.

Tag filtering.

sets.intersects(resource.tags, ['production', 'staging'])

Check whether a resource belongs to a target environment.

Feature flags.

sets.intersects(user.features, ['beta', 'preview'])

Check whether a user has access to beta features.

Category matching.

sets.intersects(product.categories, filter.categories)

Check whether a product belongs to any selected category.

Permission validation.

sets.intersects(user.permissions, required_permissions)

Check whether a user has at least one required permission.

Multiple values check.

sets.intersects([user.status], ['active', 'pending', 'trial'])

Apply OR-style matching across multiple values.

Examples๐Ÿ”—

sets.intersects([1, 2, 3], [3, 4, 5])

sets.intersects([1, 2, 3], [3, 4, 5])

Output: true

sets.intersects([1, 2, 3], [4, 5, 6])

sets.intersects([1, 2, 3], [4, 5, 6])

Output: false

sets.intersects(['admin', 'user'], ['admin', 'owner'])

sets.intersects(['admin', 'user'], ['admin', 'owner'])

Output: true

sets.intersects([1, 2, 3], [1, 2, 3])

sets.intersects([1, 2, 3], [1, 2, 3])

Output: true

sha1sum๐Ÿ”—

Returns the computed SHA-1 digest for the provided string.

Input and output๐Ÿ”—

sha1sum(string) -> bytes

Examples๐Ÿ”—

sha1sum("Hello").toHex()

sha1sum("Hello").toHex()

Output: "f7ff9e8b7bb2e09b70935a5d785e0cc5d9d0abf0"

sha256sum๐Ÿ”—

Returns the computed SHA-256 digest for the provided string.

Input and output๐Ÿ”—

sha256sum(string) -> bytes

Examples๐Ÿ”—

sha256sum("Hello").toHex()

sha256sum("Hello").toHex()

Output: "185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969"

sha512sum๐Ÿ”—

Returns the computed SHA-512 digest for the provided string.

Input and output๐Ÿ”—

sha512sum(string) -> bytes

Examples๐Ÿ”—

sha512sum("Hello").toHex()

sha512sum("Hello").toHex()

Output: "3615f80c9d293ed7402687f94b22d58e529b8cc7916f8fac7fddf7fbd5af4cf777d3d795a7a00a16bf7e7f3fb9561ee9baae480da9fe7a18769e71886b03f315"

slice๐Ÿ”—

Extracts a portion of a list between two indices.

Input and output๐Ÿ”—

list.slice(int, int) -> list

Extracts a sub-list from the start index (inclusive) to the end index (exclusive).

Indices are zero-based.

Use cases๐Ÿ”—

Pagination.

results.slice(page * pageSize, (page + 1) * pageSize)

Extract a page of results.

Take the first N elements.

list.slice(0, 5)

Get the first five elements.

Skip the first N elements.

list.slice(3, list.size())

Skip the first three elements.

Get a middle section.

list.slice(2, 8)

Extract a middle portion of the list.

Get the last N elements.

list.slice(list.size() - 3, list.size())

Get the last three elements.

sort๐Ÿ”—

Returns a copy of the provided list sorted in ascending order.

The sort order can be reversed to descending by specifying "desc" as the second argument.

Input and output๐Ÿ”—

sort(list) -> list
sort(list, string) -> list

Examples๐Ÿ”—

sort(["a", "c", "b"])

sort(["a", "c", "b"])

Output: ["a", "b", "c"]

sort([3, 2, 1], "desc")

sort([3, 2, 1], "desc")

Output: [3, 2, 1]

sortBy๐Ÿ”—

Sorts a list by a computed key expression, allowing custom sort criteria.

Input and output๐Ÿ”—

list.sortBy(var, key_expression) -> list

Sorts the list based on values computed by the key expression for each element.

The variable name is bound to each element during key computation.

Elements are sorted by their computed keys in ascending order.

Use cases๐Ÿ”—

Sort by object property.

users.sortBy(u, u.name)

Sort users alphabetically by name.

Sort by age.

users.sortBy(u, u.age)

Sort users by age.

Descending sort.

scores.sortBy(s, -s.value)

Sort scores in descending order.

Sort by computed value.

products.sortBy(p, p.price * (1 - p.discount))

Sort by the final discounted price.

Sort by string length.

words.sortBy(w, w.size())

Sort words by length.

Sort by multiple criteria.

items.sortBy(i, string(i.priority) + i.name)

Sort by priority and then by name.

Sort by distance.

locations.sortBy(loc, math.abs(loc.lat - target.lat) + math.abs(loc.lon - target.lon))

Sort locations by Manhattan distance.

Sort by Boolean value.

items.sortBy(i, i.active)

Sort with false values first and true values last.

Case insensitive sorting.

names.sortBy(n, n.lowerAscii())

Sort strings without regard to case.

Sort by nested property.

orders.sortBy(o, o.customer.tier)

Sort by a nested property.

Complex calculations.

tasks.sortBy(t, t.priority * 10 + (t.dueDate - now).getHours())

Sort using a weighted priority and time calculation.

Notes๐Ÿ”—

  • Returns a new sorted list.
  • The original list is unchanged.
  • The key expression is evaluated for each element.
  • Sorting is stable, meaning equal keys keep their relative order.
  • Keys must be comparable.
  • Negate numeric values to perform a descending sort.

Examples๐Ÿ”—

[3, 1, 4, 1, 5, 9].sortBy(x, x)

[3, 1, 4, 1, 5, 9].sortBy(x, x)

Output: [1, 1, 3, 4, 5, 9]

Sort using the value itself as the key.

[3, 1, 4, 1, 5, 9].sortBy(x, -x)

[3, 1, 4, 1, 5, 9].sortBy(x, -x)

Output: [9, 5, 4, 3, 1, 1]

Sort in descending order.

split๐Ÿ”—

Splits a string into a list using the specified delimiter.

Input and output๐Ÿ”—

string.split(string) -> list
string.split(string, int) -> list

Splits the string into a list of substrings using the delimiter.

The optional second argument limits the number of splits. Use -1 for all splits.

Examples๐Ÿ”—

'hello world'.split(' ')

'hello world'.split(' ')

Output: ["hello", "world"]

'a,b,c,d'.split(',')

'a,b,c,d'.split(',')

Output: ["a", "b", "c", "d"]

'a,b,c,d'.split(',', 2)

'a,b,c,d'.split(',', 2)

Output: ["a", "b,c,d"]

'one'.split('')

'one'.split('')

Output: ["o", "n", "e"]

substring๐Ÿ”—

Extracts a portion of a string between two indices.

Input and output๐Ÿ”—

string.substring(int) -> string
string.substring(int, int) -> string

Extracts a substring starting at the first index.

If a second argument is provided, extraction stops before that index.

If only one argument is provided, extraction continues to the end of the string.

Examples๐Ÿ”—

'hello world'.substring(0, 5)

'hello world'.substring(0, 5)

Output: "hello"

'hello world'.substring(6)

'hello world'.substring(6)

Output: "world"

'hello world'.substring(6, 11)

'hello world'.substring(6, 11)

Output: "world"

'hello'.substring(1, 4)

'hello'.substring(1, 4)

Output: "ell"

take๐Ÿ”—

Returns the first x elements of a list, or the elements between a start and end position.

Input and output๐Ÿ”—

take(list, int) -> list
take(list, int, int) -> list

Examples๐Ÿ”—

take(["a", "c", "b"], 1)

take(["a", "c", "b"], 1)

Output: ["a"]

take(["a", "c", "b"], 0, 2)

take(["a", "c", "b"], 0, 2)

Output: ["a", "c"]

tenantAllowResponseActions๐Ÿ”—

Checks whether response actions are allowed for a tenant.

Input and output๐Ÿ”—

tenantAllowResponseActions(map) -> bool

Examples๐Ÿ”—

tenantAllowResponseActions(tenant)

tenantAllowResponseActions(tenant)

Output: true

tenantCentralAccountOrigin๐Ÿ”—

Returns the accountOrigin value from the centralTenant map.

Input and output๐Ÿ”—

tenantCentralAccountOrigin(map) -> string

Examples๐Ÿ”—

tenantCentralAccountOrigin(tenant)

tenantCentralAccountOrigin(tenant)

Output: "taegis"

tenantCentralAccountType๐Ÿ”—

Returns the accountType value from the centralTenant map.

Input and output๐Ÿ”—

tenantCentralAccountType(map) -> string

Examples๐Ÿ”—

tenantCentralAccountType(tenant)

tenantCentralAccountType(tenant)

Output: "tenant"

tenantCentralDataRegion๐Ÿ”—

Returns the dataRegion value from the centralTenant map.

Input and output๐Ÿ”—

tenantCentralDataRegion(map) -> string

Examples๐Ÿ”—

tenantCentralDataRegion(tenant)

tenantCentralDataRegion(tenant)

Output: "us03"

tenantCentralId๐Ÿ”—

Returns the central tenant ID from the centralTenant map.

Input and output๐Ÿ”—

tenantCentralId(map) -> string

Examples๐Ÿ”—

tenantCentralId(tenant)

tenantCentralId(tenant)

Output: "7f8f1dee-98da-4b1b-bb70-1f788254687e"

tenantCentralLastRefresh๐Ÿ”—

Returns the lastRefresh value from the centralTenant map.

Input and output๐Ÿ”—

tenantCentralLastRefresh(map) -> string

Examples๐Ÿ”—

tenantCentralLastRefresh(tenant)

tenantCentralLastRefresh(tenant)

Output: "2025-09-23T17:28:01.113261229Z"

tenantCentralRegion๐Ÿ”—

Returns the region value from the centralTenant map.

Input and output๐Ÿ”—

tenantCentralRegion(map) -> string

Examples๐Ÿ”—

tenantCentralRegion(tenant)

tenantCentralRegion(tenant)

Output: "us-east-2"

tenantCentralXdrOwnership๐Ÿ”—

Returns the xdrOwnership value from the centralTenant map.

Input and output๐Ÿ”—

tenantCentralXdrOwnership(map) -> string

Examples๐Ÿ”—

tenantCentralXdrOwnership(tenant)

tenantCentralXdrOwnership(tenant)

Output: "securityOperations"

tenantDataRetentionMonths๐Ÿ”—

Extracts the data retention period in months from a tenant map.

Input and output๐Ÿ”—

tenantDataRetentionMonths(map) -> int

Examples๐Ÿ”—

tenantDataRetentionMonths(tenant)

tenantDataRetentionMonths(tenant)

Output: 60

tenantDescription๐Ÿ”—

Extracts the tenant description from a tenant map.

Input and output๐Ÿ”—

tenantDescription(map) -> string

Examples๐Ÿ”—

tenantDescription(tenant)

tenantDescription(tenant)

Output: "CTPx Playground"

tenantEnabled๐Ÿ”—

Checks whether a tenant is enabled.

Input and output๐Ÿ”—

tenantEnabled(map) -> bool

Examples๐Ÿ”—

tenantEnabled(tenant)

tenantEnabled(tenant)

Output: true

tenantEnvironments๐Ÿ”—

Returns a list of environment names for a tenant.

Input and output๐Ÿ”—

tenantEnvironments(map) -> list

Examples๐Ÿ”—

tenantEnvironments(tenant)

tenantEnvironments(tenant)

Output: ["pilot", "pilot_1", "pilot_2"]

tenantHasService๐Ÿ”—

Checks whether a tenant has a specific service by name (case insensitive).

Input and output๐Ÿ”—

tenantHasService(map, string) -> bool

Examples๐Ÿ”—

tenantHasService(tenant, "MDR")

tenantHasService(tenant, "MDR")

Output: true

tenantId๐Ÿ”—

Extracts the tenant ID from a tenant map.

Input and output๐Ÿ”—

tenantId(map) -> string

Examples๐Ÿ”—

tenantId(tenant)

tenantId(tenant)

Output: "11772"

tenantIsOrganization๐Ÿ”—

Checks whether a tenant is an organization.

Input and output๐Ÿ”—

tenantIsOrganization(map) -> bool

Examples๐Ÿ”—

tenantIsOrganization(tenant)

tenantIsOrganization(tenant)

Output: false

tenantIsPartner๐Ÿ”—

Checks whether a tenant is a partner.

Input and output๐Ÿ”—

tenantIsPartner(map) -> bool

Examples๐Ÿ”—

tenantIsPartner(tenant)

tenantIsPartner(tenant)

Output: false

tenantIsSophosMDR๐Ÿ”—

Returns true when the tenant's licenseLevel is exactly "MDR".

This macro is equivalent to:

tenant.licenseLevel == 'MDR'

Input and output๐Ÿ”—

tenantIsSophosMDR(map) -> bool

Examples๐Ÿ”—

tenantIsSophosMDR(tenant)

tenantIsSophosMDR(tenant)

Output: true

tenantIsSophosXDR๐Ÿ”—

Returns true when the tenant is an XDR customer.

Equivalent to:

tenantCentralXdrOwnership(tenant) != 'taegis' &&
tenantCentralXdrOwnership(tenant) != '' &&
tenant.licenseLevel != 'MDR'

Input and output๐Ÿ”—

tenantIsSophosXDR(map) -> bool

Examples๐Ÿ”—

tenantIsSophosXDR(tenant)

tenantIsSophosXDR(tenant)

Output: true

tenantLabelValue๐Ÿ”—

Returns the value of a specific label for a tenant.

Input and output๐Ÿ”—

tenantLabelValue(map, string) -> string

Examples๐Ÿ”—

tenantLabelValue(tenant, "testing")

tenantLabelValue(tenant, "testing")

Output: "true"

tenantLabels๐Ÿ”—

Returns a map of label names to values for a tenant.

Input and output๐Ÿ”—

tenantLabels(map) -> map

Examples๐Ÿ”—

tenantLabels(tenant)

tenantLabels(tenant)

Output: {"testing": "true", "Endpoints Licensed": "2000"}

tenantName๐Ÿ”—

Extracts the tenant name from a tenant map.

Input and output๐Ÿ”—

tenantName(map) -> string

Examples๐Ÿ”—

tenantName(tenant)

tenantName(tenant)

Output: "CTPx Playground"

tenantOrganization๐Ÿ”—

Extracts the organization from a tenant map.

Input and output๐Ÿ”—

tenantOrganization(map) -> string

Examples๐Ÿ”—

tenantOrganization(tenant)

tenantOrganization(tenant)

Output: ""

tenantParent๐Ÿ”—

Extracts the parent tenant ID from a tenant map.

Input and output๐Ÿ”—

tenantParent(map) -> string

Examples๐Ÿ”—

tenantParent(tenant)

tenantParent(tenant)

Output: "5000"

tenantParentId๐Ÿ”—

Extracts the parent tenant ID from a tenant map.

Input and output๐Ÿ”—

tenantParentId(map) -> string

Examples๐Ÿ”—

tenantParentId(tenant)

tenantParentId(tenant)

Output: "5000"

tenantPartner๐Ÿ”—

Extracts the partner tenant ID from a tenant map.

Input and output๐Ÿ”—

tenantPartner(map) -> string

Examples๐Ÿ”—

tenantPartner(tenant)

tenantPartner(tenant)

Output: "5000"

tenantPartnerId๐Ÿ”—

Extracts the partner tenant ID from a tenant map.

Input and output๐Ÿ”—

tenantPartnerId(map) -> string

Examples๐Ÿ”—

tenantPartnerId(tenant)

tenantPartnerId(tenant)

Output: "5000"

tenantServices๐Ÿ”—

Returns a list of service names for a tenant.

Input and output๐Ÿ”—

tenantServices(map) -> list

Examples๐Ÿ”—

tenantServices(tenant)

tenantServices(tenant)

Output: ["Access Point", "Ask an Expert", "Data Retention: 60 mo"]

tenantSupportEnabled๐Ÿ”—

Checks whether support is enabled for a tenant.

Input and output๐Ÿ”—

tenantSupportEnabled(map) -> bool

Examples๐Ÿ”—

tenantSupportEnabled(tenant)

tenantSupportEnabled(tenant)

Output: false

toHTML๐Ÿ”—

Returns the provided string as HTML.

Input and output๐Ÿ”—

toHTML(string) -> string

Examples๐Ÿ”—

'**bold**'.toHTML()

'**bold**'.toHTML()

Output: "bold"

toHex๐Ÿ”—

Returns the hexadecimal string representation of a byte list.

Input and output๐Ÿ”—

toHex(bytes) -> string

Examples๐Ÿ”—

md5sum("Hello").toHex()

md5sum("Hello").toHex()

Output: "8b1a9953c4611296a827abf8c47804d7"

toLower๐Ÿ”—

Returns a copy of the string with all characters converted to lowercase.

Input and output๐Ÿ”—

toLower(string) -> string

Examples๐Ÿ”—

"TEST".toLower()

"TEST".toLower()

Output: "test"

toPreferredTimestamp๐Ÿ”—

Returns the user's preferred timestamp format based on the specified timestamp, timezone, and language.

Input and output๐Ÿ”—

toPreferredTimestamp(string, string, string) -> string

Examples๐Ÿ”—

toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')

toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')

Output: "Jan 2 2025 15:04 UTC"

toString๐Ÿ”—

Returns the provided value of any data type as a string.

Input and output๐Ÿ”—

toString(any) -> string

Examples๐Ÿ”—

toString(100)

toString(100)

Output: "100"

toTable๐Ÿ”—

Returns a string representation of the provided data as a text or Markdown table.

Input and output๐Ÿ”—

toTable(list, list, list, bool) -> string

Examples๐Ÿ”—

toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)

toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)

Output: "+------+------+\n HEADER1 HEADER2 \n+------+------+\n row1_column1 row1_column2 \n row2_column1 row2_column2 \n+------+------+"

toTimestamp๐Ÿ”—

Returns a timestamp from a date and time string.

Input and output๐Ÿ”—

toTimestamp(string) -> timestamp

Examples๐Ÿ”—

'1/1/2012'.toTimestamp()

'1/1/2012'.toTimestamp()

Output: "2012-01-01T00:00:00Z"

toTitle๐Ÿ”—

Returns a copy of the string with the first letter of each word converted to uppercase.

Input and output๐Ÿ”—

toTitle(string) -> string

Examples๐Ÿ”—

'hello world'.toTitle()

'hello world'.toTitle()

Output: "Hello World"

toURLQuery๐Ÿ”—

Returns a copy of the string with URL special characters converted to escape sequences.

Input and output๐Ÿ”—

toURLQuery(string) -> string

Examples๐Ÿ”—

'hello world'.toURLQuery()

'hello world'.toURLQuery()

Output: "hello+world"

toUpper๐Ÿ”—

Returns a copy of the string with all characters converted to uppercase.

Input and output๐Ÿ”—

toUpper(string) -> string

Examples๐Ÿ”—

"hello".toUpper()

"hello".toUpper()

Output: "HELLO"

transformList๐Ÿ”—

Iterates on a list or map with an index/key and value, transforming each element into a new list.

Input and output๐Ÿ”—

list.transformList(index, value, expression) -> list
list.transformList(index, value, condition, expression) -> list
map.transformList(key, value, expression) -> list
map.transformList(key, value, condition, expression) -> list

Provides access to both the index/key and value in the transformation expression.

Optionally supports a filter condition.

Examples๐Ÿ”—

[1, 2, 3].transformList(i, v, i * v)

[1, 2, 3].transformList(i, v, i * v)

Output: [0, 2, 6]

[10, 20, 30].transformList(i, v, v + i)

[10, 20, 30].transformList(i, v, v + i)

Output: [10, 21, 32]

[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)

[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)

Output: [0, 6]

transformMap๐Ÿ”—

Iterates on a list or map with an index/key and value, transforming values while preserving keys.

Input and output๐Ÿ”—

list.transformMap(index, value, expression) -> map
list.transformMap(index, value, condition, expression) -> map
map.transformMap(key, value, expression) -> map
map.transformMap(key, value, condition, expression) -> map

Provides access to both the index/key and value in the transformation expression.

Optionally supports a filter condition.

Examples๐Ÿ”—

[10, 20, 30].transformMap(i, v, v * 2)

[10, 20, 30].transformMap(i, v, v * 2)

Output: {"0": 20, "1": 40, "2": 60}

[1, 2, 3].transformMap(i, v, i * v)

[1, 2, 3].transformMap(i, v, i * v)

Output: {"0": 0, "1": 2, "2": 6}

[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)

[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)

Output: {"0": 0, "2": 6}

{'a': 1, 'b': 2}.transformMap(k, v, v * 10)

{'a': 1, 'b': 2}.transformMap(k, v, v * 10)

Output: {"a": 10, "b": 20}

transformMapEntry๐Ÿ”—

Iterates on a list or map with an index/key and value, creating custom key-value pairs in a new map.

Input and output๐Ÿ”—

list.transformMapEntry(index, value, expression) -> map
list.transformMapEntry(index, value, condition, expression) -> map
map.transformMapEntry(key, value, expression) -> map
map.transformMapEntry(key, value, condition, expression) -> map

The transformation expression must produce a map literal containing a single entry.

Examples๐Ÿ”—

[1, 2, 3].transformMapEntry(i, v, {string(v): i})

[1, 2, 3].transformMapEntry(i, v, {string(v): i})

Output: {"1": 0, "2": 1, "3": 2}

['a', 'b', 'c'].transformMapEntry(i, v, {v: i})

['a', 'b', 'c'].transformMapEntry(i, v, {v: i})

Output: {"a": 0, "b": 1, "c": 2}

[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})

[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})

Output: {"1": 0, "3": 2}

{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})

{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})

Output: {"1": "a", "2": "b"}

trim (string or list)๐Ÿ”—

Removes leading and trailing whitespace.

Input and output๐Ÿ”—

trim(string) -> string
trim(list) -> list

Examples๐Ÿ”—

" 1 ".trim()

" 1 ".trim()

Output: "1"

trim([" 1 ", " 2 ", " 3 "])

trim([" 1 ", " 2 ", " 3 "])

Output: ["1", "2", "3"]

trim (string)๐Ÿ”—

Removes leading and trailing whitespace from the string.

Input and output๐Ÿ”—

string.trim() -> string

Removes spaces, tabs, and newline characters from the beginning and end of the string.

Does not remove whitespace from the middle of the string.

Examples๐Ÿ”—

' hello '.trim()

' hello '.trim()

Output: "hello"

'hello world'.trim()

'hello world'.trim()

Output: "hello world"

'\\n\\t test \\n'.trim()

'\\n\\t test \\n'.trim()

Output: "test"

' hello world '.trim()

' hello world '.trim()

Output: "hello world"

unique๐Ÿ”—

Returns a copy of the list with duplicate elements removed.

Only elements that are exactly the same (case-sensitive) are removed.

Input and output๐Ÿ”—

unique(list) -> list

Examples๐Ÿ”—

unique(["a", "b", "a"])

unique(["a", "b", "a"])

Output: ["a", "b"]

unwrapOpt๐Ÿ”—

Returns a list containing only the values from optional elements that have values, filtering out optional.none().

Input and output๐Ÿ”—

list(optional(T)).unwrapOpt() -> list(T)

Takes a list of optional values and returns a new list containing only the values from optionals that contain values.

Filters out all optional.none() entries.

Use cases๐Ÿ”—

Filter present values.

[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()

Output: [1, 3]

Remove empty optionals.

Safe map access.

keys.map(k, data[?k]).unwrapOpt()

Get values for existing keys only.

Clean results.

items.map(i, i.?value).unwrapOpt()

Extract only values that are present.

Conditional collection.

data.map(x, x > 0 ? optional.of(x) : optional.none()).unwrapOpt()

Collect values that meet a condition.

Compact operation.

optionalList.unwrapOpt()

Remove all optional.none() values.

Safe transformations.

inputs.map(i, parseValue(i)).unwrapOpt()

Keep only successfully parsed values.

Notes๐Ÿ”—

  • Input: list(optional(T))
  • Output: list(T)
  • Includes only optionals where .hasValue() returns true.
  • Maintains the order of non-empty values.
  • Returns an empty list when all optionals are empty.
  • Also available as optional.unwrap(list).

Examples๐Ÿ”—

[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()

[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()

Output: [1, 2, 3]

All values are present.

[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()

[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()

Output: [1, 3]

Filter out empty optionals.

[optional.none(), optional.none()].unwrapOpt()

[optional.none(), optional.none()].unwrapOpt()

Output: []

All values are empty.

[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]

[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]

Output: 1

Access the first present value.

upperAscii๐Ÿ”—

Converts all ASCII characters in the string to uppercase.

Input and output๐Ÿ”—

string.upperAscii() -> string

Converts all ASCII lowercase letters (a-z) to uppercase (A-Z).

Non-ASCII characters are left unchanged.

Examples๐Ÿ”—

'hello World'.upperAscii()

'hello World'.upperAscii()

Output: "HELLO WORLD"

'abc123xyz'.upperAscii()

'abc123xyz'.upperAscii()

Output: "ABC123XYZ"

'cafรฉ'.upperAscii()

'cafรฉ'.upperAscii()

Output: "CAFรฉ"

userIds๐Ÿ”—

Parses an alert or entity and returns a list of user IDs.

Input and output๐Ÿ”—

userIds(map) -> list

Examples๐Ÿ”—

userIds(inputs)

userIds(inputs)

Output: ["1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]

userInDomain๐Ÿ”—

Returns true if the provided username belongs to one or more of the provided domains.

Input and output๐Ÿ”—

userInDomain(string, list) -> bool

Examples๐Ÿ”—

userInDomain("asdf@example.com", ["example.com"])

userInDomain("asdf@example.com", ["example.com"])

Output: true

userNames๐Ÿ”—

Parses an alert or entity and returns a list of usernames.

Input and output๐Ÿ”—

userNames(map) -> list

Examples๐Ÿ”—

userNames(inputs)

userNames(inputs)

Output: ["sample_user", "another_sample_user"]

users๐Ÿ”—

Parses an alert or entity and returns a list of usernames and user IDs.

Input and output๐Ÿ”—

users(map) -> list

Examples๐Ÿ”—

users(inputs)

users(inputs)

Output: ["sample_user", "another_sample_user", "1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]

value๐Ÿ”—

Returns the value from the optional, or raises an error if the optional is empty.

Input and output๐Ÿ”—

optional(T).value() -> T

Extracts the value from an optional.

If the optional is empty (optional.none()), this causes a runtime error.

Use cases๐Ÿ”—

Extract a known value.

optional.of(42).value()

Output: 42

Get the value directly.

Extract after validation.

opt.hasValue() ? opt.value() : 'default'

Check before extraction.

Fail fast.

requiredField.value()

Raise an error if the field is missing.

Unwrap a result.

computation().value()

Get the result or fail.

Notes๐Ÿ”—

  • Calling .value() on optional.none() causes an error.
  • Always check with .hasValue() first, or use .orValue() instead.
  • Use only when you're certain the optional contains a value.
  • Useful when absence should be treated as an error.
  • For optional chaining, use .orValue().
  • Common in fail-fast scenarios.

Examples๐Ÿ”—

optional.of(42).value()

optional.of(42).value()

Output: 42

Extract an integer value.

optional.of('text').value()

optional.of('text').value()

Output: 'text'

Extract a string value.

[1, 2, 3].first().value()

[1, 2, 3].first().value()

Output: 1

Extract the first element from a list.