Data sources #
Data sources are plugin integrations that fetch structured data into the BlackStork evaluation context. They allow you to query local files, external security platforms (such as SIEMs or TIPs), standard APIs, and databases so the data can be referenced by your content blocks.
Available data sources #
jira_issues
blackstork/atlassian
v1.0.0
file
blackstork/builtin
v1.0.0
http
blackstork/builtin
v1.0.0
rss
blackstork/builtin
v1.0.0
sleep
blackstork/builtin
v1.0.0
falcon_cspm_ioms
blackstork/crowdstrike
v1.0.0
falcon_detection_details
blackstork/crowdstrike
v1.0.0
falcon_discover_host_details
blackstork/crowdstrike
v1.0.0
falcon_intel_indicators
blackstork/crowdstrike
v1.0.0
falcon_vulnerabilities
blackstork/crowdstrike
v1.0.0
eclecticiq_entities
blackstork/eclecticiq
v1.0.0
elastic_security_cases
blackstork/elastic
v1.0.0
elasticsearch
blackstork/elastic
v1.0.0
github_issues
blackstork/github
v1.0.0
graphql
blackstork/graphql
v1.0.0
hackerone_reports
blackstork/hackerone
v1.0.0
iris_alerts
blackstork/iris
v1.0.0
iris_cases
blackstork/iris
v1.0.0
microsoft_graph
blackstork/microsoft
v1.0.0
microsoft_security
blackstork/microsoft
v1.0.0
microsoft_security_query
blackstork/microsoft
v1.0.0
microsoft_sentinel_incidents
blackstork/microsoft
v1.0.0
misp_events
blackstork/misp
v1.0.0
nist_nvd_cves
blackstork/nist_nvd
v1.0.0
opencti
blackstork/opencti
v1.0.0
postgresql
blackstork/postgresql
v1.0.0
snyk_issues
blackstork/snyk
v1.0.0
splunk_search
blackstork/splunk
v1.0.0
sqlite
blackstork/sqlite
v1.0.0
terraform_state_local
blackstork/terraform
v1.0.0
virustotal_api_usage
blackstork/virustotal
v1.0.0