Exterro FTK
Use the Exterro FTK integration to protect against and provide additional visibility into phishing and other malicious email attacks.
Forensics & Malware Analysis · Exterro/AccessData
Details
| ID | Exterro FTK |
|---|---|
| Provider | Exterro |
| Category | Forensics & Malware Analysis |
| From Version | 6.2.0 |
| Docker Image | demisto/accessdata:1.1.0.10133006 |
| Supported Modules | Agentix XSIAM |
README
Use the Exterro package to integrate with the Exterro FTK platform enabling the automation of case/evidence management and endpoint collection.
Documentation for the integration was provided by FTK Connect.
Configure Exterro in Cortex
| Parameter | Description | Example |
|---|---|---|
| Name | A meaningful name for the integration instance. | FTKC Instance |
| Web Protocol | Protocol used in the FTKC server | https (or) https |
| Service URL | The URL to the FTKC server, including the scheme. | FQDN or IP address in X.X.X.X format with scheme specified. |
| Service Listening Port | The Port to the FTKC server. | 4443 |
| The API authentication key | A piece of data that servers use to verify for authenticity | eea810f5-a6f6 |
| The path to the public certificate required to authenticate | When selected, certificates are not checked. | N/A |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.
Trigger Automation Workflow in FTK Connect
Triggers the automation job and returns a string.
Base Command
exterro-ftk-trigger-workflow
Input
| Argument Name | Description | Required |
|---|---|---|
| automation_id | The Id of the automation workflow. | Required |
| case_name | The name of the case. | Optional |
| case_ids | Value of caseids. | Optional |
| evidence_path | The filepath of the evidence. | Optional |
| target_ips | Targetips for the collection. | Optional |
| search_tag_path | The filepath of the search and tag. | Optional |
| export_path | The path to export files. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ExterroFTK.Workflow.Status | string | The Status of the automation workflow trigger. |
Command Example
If automation workflow Id 232 is designed for Agent Memory collection in FTK Connect, then below command can be used to trigger the automation job from cortex xsoar.
exterro-ftk-trigger-workflow automation_id=232 target_ips=X.X.X.X
Command Example
If automation workflow Id 233 is designed to create new case, add and process the evidence from provided path in FTK Connect, then below command can be used to trigger the automation job from cortex xsoar.
exterro-ftk-trigger-workflow automation_id=233 case_name="Test case_name" evidence_path="\\X.X.X.X\ProjectData\Evidences\AR"
Context Example
{
ExterroFTK.Workflow
{
'Status': True
}
}
Human Readable Output
True
Configuration parameters
protocol— Web Protocol (required)server— Service URL (FQDN or IP Address.) (required)port— Service Listening Port (required)apikey— The API authentication key. http://support.accessdata.com/hc/en-us/articles/360053994573-Generating-API-Keys (required)public_cert— The path to the public certificate required to authenticate.
Commands (1)
-
exterro-ftk-trigger-workflowReturns a boolean value.
commonfields: id: Exterro FTK version: -1 name: Exterro FTK display: Exterro FTK category: Forensics & Malware Analysis provider: Exterro description: Use the Exterro FTK integration to protect against and provide additional visibility into phishing and other malicious email attacks. configuration: - display: Web Protocol name: protocol defaultvalue: http type: 0 required: true - display: Service URL (FQDN or IP Address.) name: server defaultvalue: localhost type: 0 required: true - display: Service Listening Port name: port defaultvalue: 4443 type: 0 required: true - display: "The API authentication key. http://support.accessdata.com/hc/en-us/articles/360053994573-Generating-API-Keys" name: apikey type: 4 required: true additionalinfo: The API authentication key has the following format `00000000-abcd-1234-5678-000000000000` - display: "The path to the public certificate required to authenticate." name: public_cert type: 0 required: false script: commands: - name: exterro-ftk-trigger-workflow arguments: - name: automation_id required: true type: number description: The Id of the automation workflow. - name: case_name description: The name of the case. - name: case_ids isArray: true description: Value of caseids. - name: evidence_path description: The filepath of the evidence. - name: target_ips isArray: true description: Targetips for the collection. - name: search_tag_path description: The filepath of the search and tag . - name: export_path description: The path to export files. outputs: - contextPath: ExterroFTK.Workflow.Status description: The Status of the of workflow trigger. type: string description: Returns a boolean value. dockerimage: demisto/accessdata:1.1.0.10133006 script: '-' type: python subtype: python3 tests: - No test fromversion: 6.2.0