AirLock Digital
Visualize your AirLock Digital application control deployment in JupiterOne — enforcement agents, policy groups and their exceptions, allowlisted applications, application categories, and blocklists — map agents to the hosts they protect, and monitor changes through queries and alerts.
- Installation
- Authorization
- Data Model
- Types
Installation
This integration connects to your self-hosted AirLock Digital server using the AirLock Digital REST API and ingests enforcement agents, policy groups, allowlisted applications, application categories, and blocklists. The server is usually on your own network, so the integration normally runs on a JupiterOne Collector that can reach the server's REST API over HTTPS (default port 3129).
Configuration in AirLock Digital
Before you configure the integration in JupiterOne, prepare the following in the AirLock Digital console:
-
The server URL of your AirLock Digital server, including the REST API port, in the format
https://server.name:3129. The JupiterOne Collector must be able to reach it. -
A user whose user group grants the REST API roles the integration needs. In the console, go to Settings, open the Users tab, and under User Group Management select the user's group. In the REST API Roles section, add the roles for the endpoints below, then click Save.
Endpoint Needed for /v1/blocklistCredential validation (always required) and the Blocklists data source /v1/agent/findEnforcement Agents /v1/groupand/v1/group/policiesPolicy Groups /v1/applicationAllowlist Applications /v1/application/categoriesApplication Categories The integration only calls these read endpoints. It never uses write, delete, or settings endpoints.
-
An API key for that user. Log in to the console as the user, open the drop-down menu with the user's name, go to My profile, and click Generate API Key. The user must have the
generate_apikeypermission. The key is displayed only once, so copy it now. -
If the server presents a self-signed or internal-CA TLS certificate, get the CA certificate in PEM format so the collector can verify the connection.
Once you have obtained the information above, proceed to JupiterOne to finalize the integration.
Configuration in JupiterOne
To install the AirLock Digital integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select AirLock Digital. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
The Account Name used to identify the AirLock Digital account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
The Server URL of your AirLock Digital server, for example
https://airlock.example.com:3129. -
The API Key generated above. It is sent in the
X-ApiKeyrequest header. -
Optionally, a CA Certificate to trust a self-signed or internal-CA certificate, or enable Disable TLS Verification to skip certificate validation (not recommended).
-
Optionally, set Agent Statuses to a comma-separated list of the numeric agent status codes reported by
/v1/agent/findto ingest only agents in those statuses. Leave it empty to ingest all agents. -
Optionally, enable Include Hidden Policy Groups to also ingest policy groups marked as hidden. By default, hidden groups are skipped.
Data Sources
Each data source can be enabled or disabled on its own. All data sources are disabled by default, so enable the ones you want to ingest.
| Data Source | Description | Entities Created |
|---|---|---|
| Enforcement Agents | AirLock Digital agents deployed on devices, with hostname, domain, OS, IP addresses, agent version, and policy version | airlock_agent |
| Policy Groups | Policy groups with their mode (audit or enforcement) and their path, publisher, parent-process, and global-process exceptions | airlock_policy |
| Allowlist Applications | Allowlisted application packages | airlock_application |
| Application Categories | Allowlist categories and their subcategories | airlock_application_category |
| Blocklists | Blocklist packages | airlock_blocklist |
The relationships between data sources are built only when both sides are enabled:
- Agent to policy group (
ASSIGNED) requires Enforcement Agents and Policy Groups. - Policy group to application (
HAS) requires Policy Groups and Allowlist Applications. - Policy group to blocklist (
HAS) requires Policy Groups and Blocklists.
Each enforcement agent is also mapped to an existing Host entity in JupiterOne with the same hostname, such as a host from your CMDB or another endpoint tool, through a PROTECTS relationship. No new Host entities are created.
Click Create once all values are provided to finalize the integration.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Additional resources
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (6)
https://<server>:3129/v1/agent/findhttps://<server>:3129/v1/applicationhttps://<server>:3129/v1/application/categorieshttps://<server>:3129/v1/blocklisthttps://<server>:3129/v1/grouphttps://<server>:3129/v1/group/policies
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (1)
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (3)
| Step | | | --- | | | Build Agent Policy Relationships | | | Build Policy Allowlist Application Relationships | | | Build Policy Blocklist Relationships | |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Account | airlock_account | Account |
| Allowlist Application | airlock_application | Configuration |
| Application Category | airlock_application_category | Configuration |
| Blocklist | airlock_blocklist | Configuration |
| Enforcement Agent | airlock_agent | HostAgent |
| Policy Group | airlock_policy | Configuration |
| Service | airlock_service | Service |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
airlock_account | PROVIDES | airlock_service |
airlock_account | HAS | airlock_agent |
airlock_account | HAS | airlock_policy |
airlock_account | HAS | airlock_application |
airlock_account | HAS | airlock_application_category |
airlock_account | HAS | airlock_blocklist |
airlock_agent | ASSIGNED | airlock_policy |
airlock_policy | HAS | airlock_application |
airlock_policy | HAS | airlock_blocklist |
Mapped Relationships
The following mapped relationships are created:
Source Entity _type | Relationship _class | Target Entity _type | Direction |
|---|---|---|---|
airlock_agent | PROTECTS | host | FORWARD |
Airlock Account
airlock_account inherits from Account
Airlock Agent
airlock_agent inherits from HostAgent
| Property | Type | Description | Specifications |
|---|---|---|---|
agentVersion * | string | null | AirLock enforcement agent client version. | |
domain * | string | null | Machine/AD domain reported by the agent. | |
hostname * | string | null | Hostname the agent reports. | |
ipAddress * | string | null | Public IP address of the agent host as seen by the server. | |
osName * | string | null | OS string reported by the agent (e.g. "Windows 10 x64"). | |
platform * | string | null | Parsed OS platform of the agent host (e.g. windows, linux, darwin). | |
policyVersion * | string | null | Policy version currently applied on the agent. | |
privateIpAddress * | string | null | Private/local IP address reported by the agent. | |
statusCode * | number | null | Raw agent status code reported by /v1/agent/find (integer). |
Airlock Application
airlock_application inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
applicationId * | string | AirLock application id. | |
version * | string | null | Application version string (may be empty). |
Airlock Application Category
airlock_application_category inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
categoryId * | string | AirLock application category id. | |
parentCategoryId * | string | null | Parent category id when this is a subcategory; null for top-level categories. |
Airlock Blocklist
airlock_blocklist inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
blocklistId * | string | AirLock blocklist id. |
Airlock Policy
airlock_policy inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
globalProcessExceptions * | array | null | Global-process exceptions configured on the policy (gprocesses[].name). | |
isAuditMode * | boolean | null | Whether the policy is in audit mode (true) vs enforcement mode (false). This is the "policy mode". | |
isGeneralisationEnabled * | boolean | null | Whether generalisation (learning) mode is enabled (generalisation flag != 0). | |
isHidden * | boolean | null | Whether the group is marked hidden in AirLock. | |
isPowershellControlled * | boolean | null | Whether PowerShell execution control is enabled (powershell flag != 0). | |
isPowershellLockdown * | boolean | null | Whether PowerShell constrained-language lockdown is enabled (pslockdown flag != 0). | |
parentGroupId * | string | null | Parent group id (or sentinel) from /v1/group. | |
parentProcessExceptions * | array | null | Parent-process exceptions configured on the policy (pprocesses[].name). | |
pathExceptions * | array | null | Allowed path exceptions configured on the policy (paths[].name). | |
publisherExceptions * | array | null | Allowed publisher exceptions configured on the policy (publishers[].name). |
Airlock Service
airlock_service inherits from Service