Getting Started
Overview and CLI Configuration
The RegScale Command Line Interface (CLI) is available for Enterprise Edition (EE) customers to perform advanced automations and to scale-out integrations for bulk data processing. The CLI is published as a Python library that can be installed via PIP which is the standard methodology for installing Python Packages. The CLI consists of several components:
- RegScale Python PIP Package - the RegScale CLI for executing commands
init.yamlfile - configuration file supporting the CLI- RegScale CLI Container - a containerized version of the CLI that contains all dependencies that are pre-installed and configured.
CLI Libraries
The CLI will continue to expand and evolve over time to support additional automations both with RegScale and with popular commercial and government tools. Each library below has its own documentation which details the list of CLI commands available for each library. The current list is shown below (broken out between internal RegScale CLI functions, government integrations, and commercial integrations):
| Command | Type | Description |
|---|---|---|
about — About | internal | Provides information about the CLI and its current version |
ad — Active Directory (AD) | commercial | Azure Active Directory (Entra ID) integration: sync App and tenant admin memberships from Entra groups into RegScale App Management |
admin_actions — Admin Actions | internal | Performs administrative actions on the RegScale platform |
alienvault — AlienVault OTX | public | AlienVault OTX Integration to load pulses to RegScale |
aqua — Aqua | commercial | Performs actions on Aqua Scanner artifacts |
archer — Archer | commercial | RSA Archer <-> RegScale bi-directional integration (login + sync commands) |
assessments — Assessment Editor | internal | Performs actions on Assessments CLI Feature to create new or update assessments to RegScale |
aws — Amazon Web Services (AWS) | commercial | AWS Integrations - Asset sync, findings, compliance, and inventory collection |
axonius — Axonius | commercial | Axonius Integration |
axonius_v2 — Axonius | commercial | Axonius V2 Integration - Sync assets and vulnerabilities from Axonius using the Axonius SDK |
azure — Azure | commercial | Azure Integrations |
bigquery — Google BigQuery | commercial | Sync assets from Google BigQuery tables into RegScale |
burp — Burp Suite | commercial | Perform actions on Burp Suite Scanner export files |
catalog — Catalog Tools | internal | Export, diagnose, and compare catalog from RegScale.com/regulations |
cci_importer — CCI Importer | public | Import CCI data from XML files and map to security controls and/or objectives. By default, maps CCIs to SecurityControl entities. Use --disable-objectives flag to also up |
change_passkey — Encrypt/Decrypt | internal | Change your encryption/decryption passkey |
cisa — DHS CISA | public | Ingest CISA threat intelligence - KEV (Known Exploited Vulnerabilities) and security alerts |
cleanup — Cleanup Tools | commercial | Cleanup tools for data management - delete issues, assets, vulnerabilities, and mappings |
compare — Compare | internal | Create RegScale Assessment of differences after comparing two files |
config — Config | internal | Updates init.yaml config parameter with value |
config_backups — Configuration Backups | internal | List or restore configuration backups. Config backups are automatically created before each save operation. Use this command to list available backups or restore from a p |
criticality_updater — Criticality Updater | public | Update the criticality of security controls in the catalog |
crowdstrike — CrowdStrike Integration | commercial | CrowdStrike Integration to load threat intelligence to RegScale (Beta) |
csam — JCAM | public | [DEPRECATED] Use regscale jcam instead; DoJ renamed CSAM to JCAM |
cve-cleanup — CVE Cleanup | public | CVE Data Cleanup Tool - Find and fix multi-CVE issue records, sync from custom fields |
databricks — Databricks | commercial | Databricks Integration to pull Scan Data from Databricks Catalogs (Beta) |
decrypt — Encrypt/Decrypt | internal | Decrypts .txt, .yaml, .json, & .csv files |
defender — Microsoft Defender | commercial | Sync assets, recommendations, and alerts from Microsoft Defender 365 and Microsoft Defender for Cloud into RegScale |
dependabot — Dependabot | commercial | Create an assessment and child issues in RegScale from Dependabot alerts |
durosuite — DuroSuite | commercial | Sync DuroSuite scan results and audits into RegScale |
ecr — Elastic Container Registry (ECR) | commercial | Performs actions on ECR Scanner artifacts |
emass — eMASS | public | eMASS Excel processing - POA&M workbook import and legacy operations |
emass_api — eMASS API | public | eMASS API integration - Bidirectional POA&M and Control sync, artifacts, and milestones |
encrypt — Encrypt/Decrypt | internal | Encrypts .txt, .yaml, .json, & .csv files |
env_info — Environment Info | internal | Display information about the current working environment |
evidence — Evidence | internal | Welcome to the RegScale Evidence Collection Automation CLI! |
fedramp — FedRAMP | public | Performs bulk processing of FedRAMP files (Upload trusted data only) |
gcp — Google Cloud Provider (GCP) | commercial | Sync assets and findings from GCP into RegScale |
gitlab — GitLab | commercial | GitLab integration to pull issues via API |
grype — Grype | commercial | Performs actions on Grype export files |
gui — CLI GUI | internal | Launch the interactive Terminal User Interface (GUI) (Beta) |
healthcheck — Health Check | internal | Monitoring tool to check the health of the RegScale instance |
ibm — IBM AppScan | commercial | Performs actions on IBM AppScan files |
import — Import | internal | Performs data processing for legacy data to migrate data formats or perform bulk processing |
import-time — Import Time | internal | Displays the total import time for the CLI |
import_all — Import All | commercial | Import scans, vulnerabilities and assets to RegScale from scan export files |
init — Init | internal | Initialize RegScale CLI environment. By default, init preserves existing user-modified values and only adds missing configuration keys from the template. Use --reset to c |
issues — Issue (POA&M) Editor | internal | Performs actions on Issues CLI Feature to create new or update issues to RegScale |
jcam — JCAM | public | Integration with DoJ's JCAM GRC Tool (Beta) |
jira — Jira | commercial | Sync issues and attachments or tasks between Jira and RegScale |
jira_dc — Jira Data Center | commercial | Sync issues, tasks, and attachments between Jira Data Center (on-prem) and RegScale |
login — Login | internal | Logs the user into their RegScale instance |
model — Model | internal | Performs actions on CLI models Feature to update issues to RegScale |
nexpose — Nexpose (Rapid 7) | commercial | Performs actions on Nexpose export files |
nist — NIST Control Sort | public | Sort the controls of a catalog in RegScale |
ocsf — OCSF | commercial | OCSF (Open Cybersecurity Schema Framework) integration for standardized security event ingestion |
okta — Okta | commercial | Okta integration to pull Okta users via API |
openscap — OpenSCAP | commercial | Sync OpenSCAP scan results (ARF, XCCDF, CSV) into RegScale |
opentext — OpenText | commercial | Performs actions on opentext export files |
orca — Orca Security | commercial | Integrate continuous monitoring data from Orca Security (agentless CNAPP) |
oscal — NIST OSCAL | public | Performs bulk processing of OSCAL files |
panw — Palo Alto Networks | commercial | Palo Alto Networks integrations: SCM Compliance Center, Prisma Cloud CSPM, and Prisma Cloud Compute |
pipeline — CI/CD Pipeline Compliance | commercial | CI/CD Pipeline Compliance - Track component-level compliance from GitLab and GitHub pipelines |
prisma — Prisma | commercial | Prisma Cloud API integration with authentication, host scans, image scans, and SBOM processing |
qradar — IBM QRadar | commercial | QRadar SIEM integration - Sync security events, findings, and assets from IBM QRadar |
qualys — Qualys | commercial | Performs actions from the Qualys API |
rapid7 — Rapid7 | commercial | Rapid7 InsightVM integration - sync assets and vulnerabilities via API |
salesforce — Salesforce | commercial | Sync data and attachments between Salesforce Cases & RegScale Issues |
sap — SAP | commercial | SAP Integration |
sarif — SARIF | commercial | SARIF integration - import vulnerabilities or sync compliance data from static analysis tools |
sbom — SBOM | commercial | Import and manage Software Bill of Materials (SBOM) files |
sentinelone — SentinelOne | commercial | Sync agents, threats, and vulnerabilities from SentinelOne into RegScale |
servicenow — ServiceNow | commercial | ServiceNow Integration - Bidirectional sync of incidents, changes, cases, and attachments |
set_permissions — Bulk Set Permissions | internal | Bulk set permissions on records in RegScale from a generated spreadsheet |
sicura — Sicura | commercial | Sync assets and findings from Sicura into RegScale |
snyk — Snyk | commercial | Performs actions on Snyk export files |
sonarcloud — SonarCloud | commercial | Sync alerts from SonarCloud API or import from GitLab SAST report files |
splunk — Splunk | commercial | Splunk integration - search, export, job management, and evidence ingestion |
stig — STIG | commercial | Sync assets, findings, and assessments from STIG .ckl files into RegScale |
stig_mapper — STIG Mapper | commercial | Map data from STIGs to RegScale |
tanium — Tanium | commercial | Sync assets, vulnerabilities, and compliance findings from Tanium into RegScale |
tenable — Tenable Vulnerability Management (Formerly Tenable IO) | commercial | Tenable Vulnerability Management (formerly Tenable.io), Tenable Security Center, and Nessus scan processing |
trivy — Trivy | commercial | Performs actions on Trivy export files |
tui — CLI GUI | internal | Launch the interactive Terminal User Interface (TUI) (Beta) |
upload_file — Upload File | internal | Upload a file from your local machine to a record in RegScale |
validate_token | internal | Check to see if token is valid |
veracode — Veracode | commercial | Performs actions on Veracode export files |
version — Version | internal | Display the CLI or RegScale application version and exit |
wiz — Wiz | commercial | Integrates continuous monitoring data from Wiz.io |
xray — Xray | commercial | Performs actions on JFrog Xray export files |
Installing the CLI
Prerequisites
- You must ensure a supported version of Python is installed on the machine ( >= 3.9.0 & <=3.13)
- Python Download
- Ensure that
pipis installed- Pip: Download
- The machine running the CLI needs to be able to access Pypi.org
- If using a proxy, set the proxy for pip
pip config set global.proxy http(s)://<proxy>:<port>
- If using a proxy, set the proxy for pip
- NOTE: If you see any warnings during the install about the PATH for RegScale, make sure you update the path with your directory.
For Linux/Mac, example here:export PYTHONPATH=$PYTHONPATH:/home/howieavp76/.local/bin.
For a Windows installation, you should update the system or user environment variables to bring in the Python scripts folder:
addC:\Users\YOURUSER\AppData\Local\Programs\Python\Python311\Scriptsto the Python Path, where Python311 denotes your version number and YOURUSER is your user name. - NOTE: Windows users require the Visual Studio C++ Build Tools available here
- NOTE: Usage of the CLI with Powershell ISE is not recommended, as it is deprecated by Microsoft. The mainline version of Powershell is recommended.
Recommended Run environment - virtual python
We strongly recommend you use a python virtual environment to run the regscale-cli to ensure isolation from other python instances on your machine. To set up a virtual environment, change to a working directory where you plan to install regscale-cli and then:
- Ensure you are calling the python install version between 3.12 and 3.14
python --version
c:\>Python.exe --version
- Create the virtual environment
python -m venv venv
c:\>Python.exe -m venv venv
- Activate the virtual environment
source venv/bin/activate
.\venv\Scripts\activate.bat
.\venv\Scripts\Activate.ps1
- To deactivate after you're done running the CLI:
deactivate
NOTE: Repeat the activation step above each time you run the CLI.
Install the CLI
The CLI is available on PyPi under the RegScale CLI Project. To install the CLI on your machine run the following commands:
# Install CLI from PyPi
python -m pip install regscale-cli
# Install CLI from PyPi
python.exe -m pip install regscale-cli
These commands will install the RegScale CLI, manually update GraphQL dependencies, create a directory for processing artifacts/logs, and then pull down a template for the init.yaml file for you to edit as shown in the next section.
Using the CLI in a Container
A common use case for the CLI is to spin up jobs at some frequency for bulk data processing. Many customers are now using containers to spin up the RegScale CLI to perform a job and then tear itself down to keep costs low in a cloud-native style architecture for data processing. To access the container, you can pull from the RegScale CLI Docker Hub:
docker pull regscale/regscale-cli:latest
Further instructions for using the CLI will be made available in the Docker Hub README.
Initialization
Initialize your CLI environment with the init command:
regscale init
The CLI will generate a default init.yaml file and prompt you for RegScale domain and to log in:
Initializing your RegScale CLI environment...
Would you like to change your RegScale domain from https://regscale.yourcompany.com/? (Y/n): y
Please enter your RegScale domain.
Example: https://mydomain.regscale.com/
Domain: https://regscale.mycomapny.com
[2023/01/20 04:32;41] INFO [2023/01/20 04:32;41] [INFO ] Valid URL provided, regscale.py:349
init.yaml has been updated.
Would you like to log in to your RegScale instance? (Y/n): y
Please enter your username: rross
Please enter your password:
In Infrastructure as Code scenarios, you can initialize your CLI environment and pass parameters inline:
regscale init --domain https://regscale.mycompany.com --username rross --password <yourpassword>
Alternatively, initialize your CLI environment and skip prompts with the --skip-prompts flag:
regscale init --skip-prompts
The CLI is driven by a set of configurations that are specified in the init.yaml file.
A sample of init.yaml file is shown below:
adAccessToken: <createdProgrammatically>
adAuthUrl: https://login.microsoftonline.com/
adClientId: <myClientIdGoesHere>
adClientSecret: <mySecretGoesHere>
adGraphUrl: https://graph.microsoft.com/.default
adTenantId: <myTenantIdGoesHere>
assessmentDays: 10
azure365AccessToken: <createdProgrammatically>
azure365ClientId: <myClientIdGoesHere>
azure365Secret: <mySecretGoesHere>
azure365TenantId: <myTenantIdGoesHere>
azureCloudAccessToken: <createdProgrammatically>
azureCloudClientId: <myClientIdGoesHere>
azureCloudSecret: <mySecretGoesHere>
azureCloudSubscriptionId: <mySubscriptionIdGoesHere>
azureCloudTenantId: <myTenantIdGoesHere>
cisaKev: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
crowdstrikeBaseUrl: <crowdstrikeApiUrl>
crowdstrikeClientId: <myClientIdGoesHere>
crowdstrikeClientSecret: <mySecretGoesHere>
dependabotId: <myGithubUserIdGoesHere>
dependabotOwner: <myGithubRepoOwnerGoesHere>
dependabotRepo: <myGithubRepoNameGoesHere>
dependabotToken: <myGithubPersonalAccessTokenGoesHere>
domain: <<filled out programmatically after logging in to RegScale>
evidenceFolder: ./evidence
failScore: 30
gcpCredentials: <path/to/credentials.json>
gcpOrganizationId: <000000000000>
gcpProjectId: <000000000000>
gcpScanType: <organization | project>
githubDomain: api.github.com
issues:
amazon:
high: 30
low: 365
minimumSeverity: low
moderate: 90
status: Open
useKev: true
aqua:
critical: 30
high: 30
low: 180
minimumSeverity: low
moderate: 90
status: Open
useKev: true
aws:
high: 30
low: 365
moderate: 90
status: Open
defender365:
high: 30
low: 365
moderate: 90
status: Open
defenderCloud:
high: 30
low: 365
moderate: 90
status: Open
ecr:
critical: 30
high: 30
low: 180
minimumSeverity: low
moderate: 90
status: Open
useKev: true
jira:
high: 30
highest: 7
low: 180
lowest: 365
medium: 90
status: Open
nexpose:
critical: 30
high: 30
low: 180
minimumSeverity: low
moderate: 90
status: Open
useKev: true
prisma:
critical: 30
high: 30
low: 180
minimumSeverity: low
moderate: 90
status: Open
useKev: true
qualys:
high: 30
low: 365
moderate: 90
status: Open
salesforce:
critical: 7
high: 30
low: 365
medium: 90
status: Open
snyk:
critical: 30
high: 30
low: 180
minimumSeverity: low
moderate: 90
status: Open
useKev: true
tenable:
critical: 3
high: 5
low: 180
minimumSeverity: low
moderate: 30
status: Draft
useKev: false
wiz:
critical: 30
high: 90
low: 365
medium: 90
status: Open
xray:
critical: 30
high: 30
low: 180
minimumSeverity: low
moderate: 90
status: Open
useKev: true
jiraApiToken: <jiraApiToken>
jiraUrl: <jiraUrl>
jiraUserName: [email protected]
maxThreads: 1000
nistCpeApiKey: <myNistCpeApiKey>
oktaApiToken: Can be a SSWS token from Okta or created programmatically
oktaClientId: <oktaClientIdGoesHere>
oktaUrl: <oktaUrlGoesHere>
oscalLocation: /opt/OSCAL
otx: enter AlienVault API key here
passScore: 80
pwshPath: /opt/microsoft/powershell/7/pwsh
qualysPassword: <qualysPassword>
qualysUrl: https://yourcompany.qualys.com/api/2.0/fo/scan/
qualysUserName: <qualysUserName>
salesforcePassword: <salesforcePassword>
salesforceToken: <salesforceSecurityToken>
salesforceUserName: <salesforceUserName>
sicuraToken: <mySicuraToken>
sicuraUrl: <mySicuraUrl>
snowPassword: <snowPassword>
snowUrl: <mySnowUrl>
snowUserName: <snowUserName>
sonarToken: <mySonarToken>
stigBatchSize: 100
tenableAccessKey: <tenableAccessKey>
tenableMinimumSeverityFilter: low
tenableSecretKey: <tenableSecretKey>
tenableUrl: https://cloud.tenable.com
timeout: 60
token: <filled out programmatically after logging in to RegScale>
userId: <filled out programmatically after logging in to RegScale>
wizAccessToken: <createdProgrammatically>
wizAuthUrl: https://auth.wiz.io/oauth/token
wizExcludes: My things to exclude here
wizInventoryFilterBy: <wizInventoryFilterBy>
wizIssueFilterBy: <wizIssueFilterBy>
wizLastInventoryPull: <wizLastInventoryPull>
wizMaxConnectionPoolWorkers: 10
wizReportAge: 15
wizScope: <filled out programmatically after authenticating to Wiz>
wizUrl: <my Wiz URL goes here>
The YAML file is read during the execution of commands and must be set properly for the CLI to execute. Each of the fields in the configuration file are described below:
domain- the URL for your instance of RegScaletoken- the JWT bearer token for authenticating requests. This can be set one of three ways:- Paste from your user profile after logging into RegScale
- Use the RegScale login CLI to authenticate which will automatically set the token in the YAML file (good for 24 hours)
- Using Administrator privileges in RegScale, create a service account which can generate a long-running token that can be used for API access. Paste this token into the YAML file.
assessmentDays- Number of days to add to today's date for new assessments created in RegScale created via RegScale CLIuserId- your RegScale user ID which is a GUID value (NOTE: This is programmatically set when logging in.)maxThreads- The total number of threads the application is allowed to use. (NOTE: Changing this number can have a negative or positive impact on performance.)
NOTE: The init.yaml file contains sensitive keys and secrets and should be stored securely. Non-RegScale configuration is described on the CLI page for each specific integration we support.
Supporting Internally Issued Certificate
Three options to allow the RegScale CLI to connect over SSL to the RegScale platform that is using a certificate signed by an internally self-signed CA.
Append to Existing CA Trust File
If the RegSale platform was deployed with a certificate from an internally self-signed CA, the CA pem encoded certificate needs to be appended to the cacert.pem file
cat ca.pem >> .local/python3.10/site-packages/certifi/cacert.pem
Using a Custom CA Bundle to Trust an Internal Signed CA
Place the CA Certificate pem file in a known location and export REQUESTS_CA_BUNDLE=/path/ca.pem
export REQUESTS_CA_BUNDLE=/path/ca.pem
Note: This will only trust certificates signed by the CA or CA root certificates in the ca.pem file.
Disabling Certificate Verification
To disable the SSL certificate verification by add ssl_verify=false to the init.yaml file
Upgrading or Uninstalling the CLI
Upgrade the CLI
If you are ready to upgrade to the latest version of the CLI, run the following command:
pip install regscale-cli --upgrade
- Manually force a specific version upgrade as follows:
pip install -i regscale-cli==1.1.8
Uninstall the CLI
To uninstall, run the following command:
pip uninstall regscale-cli
Updated 13 days ago
