TaegisXDR Deprecated
Deprecated. Use TaegisXDR v2 instead.
Data Enrichment & Threat Intelligence · Secureworks
Details
| ID | TaegisXDR |
|---|---|
| Provider | Sophos |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.5.0 |
| Docker Image | demisto/python3:3.10.12.65389 |
| Supported Modules | Agentix XSIAM |
README
Configure Taegis XDR in Cortex
| Parameter | Description | Required |
|---|---|---|
| Taegis Environment | The environment to utilize | True |
| Client ID | Client ID as described in the Taegis Documentation | True |
| Client Secret | Client Secret as described in the Taegis Documentation | True |
| Use system proxy settings | Defines whether the system proxy is used or not | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
taegis-archive-investigation
Base Command
!taegis-archive-investigation
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | The investigation id to archive | True |
Command Example
!taegis-archive-investigation id=c207ca4c-8a78-4408-a056-49f05d6eb77d
Context Example
{
"TaegisXDR": {
"ArchivedInvestigation": {
"id": "c207ca4c-8a78-4408-a056-49f05d6eb77d"
}
}
}
taegis-create-comment
Base Command
!taegis-create-comment
Inputs
| Argument Name | Description | Required |
|---|---|---|
| comment | The comment string to add to the investigation | True |
| parent_id | The investigation ID to add the comment to | True |
Command Example
!taegis-create-comment comment="This is a test comment" parent_id="219da0ee-8642-4363-827c-8a6fbd479082"
Context Example
{
"TaegisXDR": {
"CommentCreate": {
"id": "593fa115-abad-4a52-9fc4-2ec403a8a1e4"
}
}
}
taegis-create-investigation
Base Command
!taegis-create-investigation
Inputs
| Argument Name | Description | Required |
|---|---|---|
| description | The subject or description of the investigation | True |
| priority | The priority for the investigiation [Default: 3] | False |
Command Example
!taegis-create-investigation priority=1 description="XSOAR Created Investigation"
Context Example
{
"TaegisXDR": {
"Investigation": {
"id": "593fa115-abad-4a52-9fc4-2ec403a8a1e4"
}
}
}
taegis-execute-playbook
Base Command
!taegis-execute-playbook
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | Playbook instance ID to execute | True |
| inputs | JSON object of inputs to pass into the playbook execution | False |
Command Example
!taegis-execute-playbook id=UGxheWJvb2tJbnN0YW5jZTphZDNmNzBlZi1mN2U0LTQ0OWYtODJiMi1hYWQwMjQzZTA2NTg=
!taegis-execute-playbook id=UGxheWJvb2tJbnN0YW5jZTphZDNmNzBlZi1mN2U0LTQ0OWYtODJiMi1hYWQwMjQzZTA2NTg= inputs=`{'myvar': 'myval'}`
Context Example
{
"id": "UGxheWJvb2tFeGVjdXRpb246NGYwZDZiNGQtNWNiZS00NDkxLTg3YzYtMDZkNjkxYzMwMTg4"
}
taegis-fetch-alerts
Base Command
!taegis-fetch-alerts
Input
| Argument Name | Description | Default | Required |
|---|---|---|---|
| ids | A list of alerts by IDs | 936c1cc1-db8f-430c-837c-1c914fcca35a |
False |
| limit | Number of results to when ids is not defined |
10 |
False |
| offset | The result to start from when ids is not defined |
0 |
False |
| cql_query | The query to utilize when searching for Alerts | from alert severity >= 0.6 and status='OPEN' |
False |
Command Examples
!taegis-fetch-alerts ids=`["6594e97f-a898-5b28-82b2-ea03293cdaa1"]`
Context Example
{
"TaegisXDR": {
"Alerts": [
{
"id": "c4f33b53-eaba-47ac-8272-199af0f7935b",
"metadata": {
"title": "Test Alert",
"description": "This is a test alert",
"severity": 0.5,
}
}
]
}
}
taegis-fetch-assets
Base Command
!taegis-fetch-assets
Input
| Argument Name | Description | Default | Required |
|---|---|---|---|
| page | 0 |
False | |
| page_size | 10 |
False | |
| endpoint_type | False | ||
| host_id | ID of the asset to fetch | e43b545a-580a-4047-b489-4338c1cc4ba1 |
False |
| hostname | False | ||
| investigation_id | False | ||
| ip_address | False | ||
| mac_address | False | ||
| os_family | False | ||
| os_version | False | ||
| sensor_version | False | ||
| username | False |
Command Examples
!taegis-fetch-assets
!taegis-fetch-assets page=1 page_size=5
!taegis-fetch-assets hostname=MyHostname01
!taegis-fetch-assets host_id=e43b545a-580a-4047-b489-4338c1cc4ba1
Context Example
{
"TaegisXDR": {
"Assets": [
{
"id": "",
"ingestTime": "",
"createdAt": "",
"updatedAt": "",
"deletedAt": "",
"biosSerial": "",
"firstDiskSerial": "",
"systemVolumeSerial": "",
"sensorVersion": "",
"endpointPlatform": "",
"hostnames": [{"id": ", "hostname": ""],
"architecture": "",
"osFamily": "",
"osVersion": "",
"osDistributor": "",
"osRelease": "",
"systemType": "",
"osCodename": "",
"kernelRelease": "",
"kernelVersion": "",
"tags": [ "key": "", "tag": ""],
"endpointType": "",
"hostId": "",
"sensorId": "",
}
]
}
}
taegis-fetch-comment
Base Command
!taegis-fetch-comment
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | The ID of the comment to fetch | True |
Command Example
!taegis-fetch-comment id=ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f
Context Example
{
"TaegisXDR": {
"Comment": {
"author_user": {
"email_normalized": "myuser@email.com",
"given_name": "John",
"family_name": "Smith",
"id": "auth0|000000000000000000000001",
},
"id": "ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f",
"comment": "This is a comment in an investigation",
"created_at": "2022-01-01T13:04:57.17234Z",
"deleted_at": None,
"modified_at": None,
"parent_id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
"parent_type": "investigation",
}
}
}
taegis-fetch-comments
Base Command
!taegis-create-comments
Inputs
| Argument Name | Description | Required |
|---|---|---|
| parent_id | The investigation ID to fetch comments for | True |
Command Example
!taegis-fetch-comments parent_id=c2e09554-833e-41a1-bc9d-8160aec0d70d
Context Example
{
"TaegisXDR": {
"Comments": [
{
"author_user": {
"email_normalized": "myuser@email.com",
"given_name": "John",
"family_name": "Smith",
"id": "auth0|000000000000000000000001",
},
"id": "ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f",
"comment": "This is a comment in an investigation",
"created_at": "2022-01-01T13:04:57.17234Z",
"deleted_at": None,
"modified_at": None,
"parent_id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
"parent_type": "investigation",
},
{
"author_user": {
"email_normalized": "myuser@email.com",
"given_name": "John",
"family_name": "Smith",
"id": "auth0|000000000000000000000001",
},
"id": "ff9ca818-4749-4ccb-883a-2ccc6f6c1234",
"comment": "This is another comment",
"created_at": "2022-01-02T13:04:57.17234Z",
"deleted_at": None,
"modified_at": None,
"parent_id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
"parent_type": "investigation",
}
]
}
}
taegis-fetch-endpoint
Base Command
!taegis-fetch-endpoint
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | Endpoint ID to fetch | True |
Command Example
!taegis-fetch-endpoint id=ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f
Context Example
{
"TaegisXDR": {
"assetEndpointInfo": {
"hostId": "",
"hostName": "",
"actualIsolationStatus": "",
"allowedDomain": "",
"desiredIsolationStatus": "",
"firstConnectTime": "",
"moduleHealth": {
"enabled": ""
"lastRunningTime": "",
"moduleDisplayName": "",
}
"lastConnectAddress": "",
"lastConnectTime": "",
"sensorVersion": ""
}
}
}
taegis-fetch-investigation
Base Command
!taegis-fetch-investigation
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | Investigation ID to lookup | True |
Command Example
!taegis-fetch-investigation id=936c1cc1-db8f-430c-837c-1c914fcca35a
Context Example
{
"TaegisXDR": {
"Investigations": [
{
"archived_at": None,
"created_at": "2022-02-02T13:53:35Z",
"description": "Test Investigation",
"id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
"key_findings": "",
"priority": 2,
"service_desk_id": "",
"service_desk_type": "",
"status": "Open",
"alerts2": [],
"url": "https://ctpx.secureworks.com/investigations/c2e09554-833e-41a1-bc9d-8160aec0d70d",
}
]
}
}
taegis-fetch-investigation-alerts
Base Command
!taegis-fetch-investigation-alerts
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | Investigation ID to lookup | True |
Command Example
!taegis-fetch-investigation-alerts id=936c1cc1-db8f-430c-837c-1c914fcca35a
Context Example
{
"TaegisXDR": {
"InvestigationAlerts": [
{
"id": "c4f33b53-eaba-47ac-8272-199af0f7935b",
"description": "Test Alert",
"message": "This is a test alert",
"severity": 0.5,
}
]
}
}
taegis-fetch-investigations
Base Command
!taegis-fetch-investigations
Inputs
| Argument Name | Description | Required |
|---|---|---|
| page | False | |
| page_size | False |
Command Example
!taegis-fetch-investigations
Context Example
{
"TaegisXDR": {
"Investigations": [
{
"description": "Test Investigation",
"id": "c2e09554-833e-41a1-bc9d-8160aec0d70d",
"key_findings": "",
"priority": 2,
"service_desk_id": "",
"service_desk_type": "",
"status": "Open"
}
]
}
}
taegis-fetch-playbook-execution
Base Command
!taegis-fetch-playbook-execution
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | Playbook execution ID to fetch | True |
Command Example
!taegis-fetch-playbook-execution id=UGxheWJvb2tFeGVjdXRpb246NGYwZDZiNGQtNWNiZS00NDkxLTg3YzYtMDZkNjkxYzMwMTg4
Context Example
{
"TaegisXDR": {
"PlaybookExecution": {
"createdAt": "2022-01-01T13:51:24Z",
"executionTime": 1442,
"id": "UGxheWJvb2tFeGVjdXRpb246NGYwZDZiNGQtNWNiZS00NDkxLTg3YzYtMDZkNjkxYzMwMTg4",
"inputs": {
"alert": {
"message": "Test Alert",
}
},
"instance": {
"name": "Test Alert Instance",
"playbook": {
"name": "Taegis.PagerDutyAlertEvent"
}
},
"outputs": "d6b65662-c1da-4109-8553-c5664918c952",
"state": "Completed",
"updatedAt": "2022-01-01T13:51:31Z"
}
}
}
taegis-fetch-users
Base Command
!taegis-fetch-users
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | The id of the user, in auth0 format |
False |
| The email of the user | False | |
| status | The users to find based on status | False |
| page | False | |
| page_size | False |
Command Example
!taegis-fetch-users id="auth0|123456"
Context Example
{
"TaegisXDR": {
"Users": [
{
"email": "myuser@email.com",
"family_name": "Smith",
"given_name": "John",
"status": "Registered",
"user_id": "auth0|123456"
}
]
}
}
taegis-isolate-asset
Base Command
!taegis-isolate-asset
Input
| Argument Name | Description | Default | Required |
|---|---|---|---|
| id | ID of the asset to isolate | e43b545a-580a-4047-b489-4338c1cc4ba1 |
True |
| reason | The reason for the isolation | See ticket 12345 |
True |
Command Examples
!taegis-isolate-asset id="e43b545a-580a-4047-b489-4338c1cc4ba1" reason="See ticket 12345"
Context Example
{
"TaegisXDR": {
"AssetIsolation": {
"id": "e43b545a-580a-4047-b489-4338c1cc4ba1"
}
}
}
taegis-update-alert-status
Base Command
!taegis-update-alert-status
Input
| Argument Name | Description | Default | Required |
|---|---|---|---|
| ids | A comma-separated list of alerts by IDs | alert://priv:crowdstrike:11772:1666269058114:59284e28-4ec8-542b-a4a1-452c3688bc1a |
True |
| status | The status to update the alert(s) with | FALSE_POSITIVE |
True |
| reason | A comment/reason for the alert status update | See ticket 13245 |
False |
Permitted Status Values
- FALSE_POSITIVE
- NOT_ACTIONABLE
- OPEN
- TRUE_POSITIVE_BENIGN
- TRUE_POSITIVE_MALICIOUS
Command Examples
!taegis-update-alert-status ids="alert://priv:crowdstrike:11772:1677742145475:07e2d9cc-0a04-55ec-890a-97f39d63698e" status=NOT_ACTIONABLE reason="Test Reason"
Context Example
{
"TaegisXDR": {
"AlertStatusUpdate": {
"reason": "feedback updates successfully applied",
"resolution_status": "SUCCESS"
}
}
}
taegis-update-comment
Base Command
!taegis-update-comment
Inputs
| Argument Name | Description | Required |
|---|---|---|
| comment | The comment string to add to the investigation | True |
| id | The comment ID to update | True |
Command Example
!taegis-update-comment id="ff9ca818-4749-4ccb-883a-2ccc6f6c9e0f" comment="Newly updated comment"
Context Example
{
"TaegisXDR": {
"CommentUpdate": {
"id": "593fa115-abad-4a52-9fc4-2ec403a8a1e4"
}
}
}
taegis-update-investigation
Base Command
!taegis-update-investigation
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | Investigation ID to update | True |
| key_findings | False | |
| prioirity | The priority of the Investigation (1-5) | False |
| service_desk_id | An ID or ticket # to relate to an Investigation | False |
| service_desk_type | The type of id related to an investigation (e.g. Jira) | False |
| status | The current status of the Investigation | False |
| assignee_id | The id of a user to assign, in auth0|12345 format |
False |
Note: At least 1 of the above inputs (in addition to id) must be defined
Permitted Status Values
- Active
- Awaiting Action
- Closed: Authorized Activity
- Closed: Confirmed Security Incident
- Closed: False Positive Alert
- Closed: Inconclusive
- Closed: Informational
- Closed: Not Vulnerable
- Closed: Threat Mitigated
- Open
- Suspended
Command Example
!taegis-update-investigation id="936c1cc1-db8f-430c-837c-1c914fcca35a" priority=3 status="Open" service_desk_id="XDR-1234" service_desk_type="Jira"
Context Example
{
"TaegisXDR": {
"InvestigationUpdate": {
"id": "c2e09554-833e-41a1-bc9d-8160aec0d70d"
}
}
}
taegis-unarchive-investigation
Base Command
!taegis-unarchive-investigation
Inputs
| Argument Name | Description | Required |
|---|---|---|
| id | The investigation id to unarchive | True |
Command Example
!taegis-unarchive-investigation id=c207ca4c-8a78-4408-a056-49f05d6eb77d
Context Example
{
"TaegisXDR": {
"UnarchivedInvestigation": {
"id": "c207ca4c-8a78-4408-a056-49f05d6eb77d"
}
}
}
Configuration parameters
environment— Taegis Environment (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingsclient_id— Client ID (required)client_secret— Client Secret (required)isFetch— Fetch incidentsmax_fetch— Maximum number of incidents per fetchfirst_fetch— First fetch time intervalincidentFetchInterval— Incidents Fetch IntervalincidentType— Incident typeinclude_assets— Include Assets in Fetch
Commands (18)
-
taegis-archive-investigationArchive an investigation
-
taegis-create-commentCreate a comment on an investigation
-
taegis-create-investigationCreate an Investigation within Taegis
-
taegis-execute-playbookExecutes a Taegis playbook instance
-
taegis-fetch-alertsList Taegis alerts by ID
-
taegis-fetch-assetsFetch assets based on search criteria
-
taegis-fetch-commentFetch comment by comment ID
-
taegis-fetch-commentsFetch comments by Parent Type and ID
-
taegis-fetch-endpointFetch endpoint information
-
taegis-fetch-investigationFetch all investigations or a specific investigation
-
taegis-fetch-investigation-alertsFetch Alert IDs related to a specific investigation
-
taegis-fetch-playbook-executionFetch the results of a Taegis playbook instance execution
-
taegis-fetch-usersFetch a user by ID or email address
-
taegis-isolate-assetIsolate a specific asset
-
taegis-unarchive-investigationUnarchive an investigation
-
taegis-update-alert-statusUpdate the status of an alert
-
taegis-update-commentUpdate an existing comment
-
taegis-update-investigationUpdate an existing investigation
commonfields: id: TaegisXDR version: -1 name: TaegisXDR display: TaegisXDR (Deprecated) deprecated: true category: Data Enrichment & Threat Intelligence provider: Sophos description: Deprecated. Use TaegisXDR v2 instead. configuration: - display: Taegis Environment name: environment type: 15 required: true options: - US1 - US2 - EU additionalinfo: Used to determine the URL and API endpoint to utilize for your tenant - display: Trust any certificate (not secure) name: insecure type: 8 defaultvalue: "false" required: false - display: Use system proxy settings name: proxy type: 8 required: false - display: Client ID name: client_id type: 4 required: true - display: Client Secret name: client_secret type: 4 required: true - display: Fetch incidents name: isFetch type: 8 required: false - name: max_fetch defaultvalue: '15' display: Maximum number of incidents per fetch type: 0 additionalinfo: The maximum limit is 200. required: false - name: first_fetch defaultvalue: 3 days display: First fetch time interval type: 0 additionalinfo: 'Date or relative timestamp to start fetching incidents from. For Alert, incidents will be fetched based on triggered date. For Event, the incidents will be fetched based on event time. (Formats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc.).' required: false - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: "1" type: 19 required: false - display: Incident type name: incidentType type: 13 required: false - display: Include Assets in Fetch name: include_assets defaultvalue: "true" type: 8 additionalinfo: An error can occur when the API is slow or there are a large numbers of assets being added to a new incident/investigation. Disabling this will fetch incidents without including asset information, allowing time for the investigation creation to be completed. required: false script: script: '' type: python commands: - name: taegis-fetch-alerts arguments: - name: ids description: A list of alert IDs or string of comma-separated alert IDs to return isArray: true - name: cql_query description: The Taegis CQL query to for searching Alerts - name: limit default: true description: Number of results to return per page defaultValue: "10" - name: offset description: The results to start with defaultValue: "0" outputs: - contextPath: TaegisXDR.Alerts description: List of Taegis alerts description: List Taegis alerts by ID - name: taegis-fetch-investigation arguments: - name: id description: The investigation ID to lookup - name: page description: The page number for fetching investigations defaultValue: "0" - name: page_size description: Number of investigations to return defaultValue: "10" - name: status description: A list of statuses to use when searching for investigations isArray: true outputs: - contextPath: TaegisXDR.Investigations description: Dictionary of the located Taegis investigation description: Fetch all investigations or a specific investigation - name: taegis-create-investigation arguments: - name: description required: true description: The description of the investigation - name: priority required: true default: true auto: PREDEFINED predefined: - "1" - "2" - "3" - "4" - "5" description: The priority of the investigation (1-5) defaultValue: "2" outputs: - contextPath: TaegisXDR.Investigation description: The investigation ID that was created description: Create an Investigation within Taegis - name: taegis-update-investigation arguments: - name: id required: true description: The investigation ID to update - name: priority description: The priority of the investigation (1-5) - name: key_findings description: The Key Findings field of the investigation - name: status auto: PREDEFINED predefined: - Open - Active - Awaiting Action - Suspended - 'Closed: Authorized Activity' - 'Closed: Confirmed Security Incident' - 'Closed: False Positive Alert' - 'Closed: Inconclusive' - 'Closed: Informational' - 'Closed: Not Vulnerable' - 'Closed: Threat Mitigated' description: New status for the investigation - name: service_desk_id description: An ticket or ID for to an external system for reference - name: service_desk_type description: The type of service desk id (e.g. XSOAR) - name: assignee_id description: The auth0 ID of a user, in 'auth0|12345' format outputs: - contextPath: TaegisXDR.InvestigationUpdate description: ID of the updated Taegis investigation description: Update an existing investigation - name: taegis-fetch-investigation-alerts arguments: - name: id required: true description: The investigation ID related to the alerts - name: page description: Page number of the investigation alerts defaultValue: "0" - name: page_size description: Number of alerts per investigation query defaultValue: "10" outputs: - contextPath: TaegisXDR.InvestigationAlerts description: List of alerts related to a Taegis investigation description: Fetch Alert IDs related to a specific investigation - name: taegis-execute-playbook arguments: - name: id required: true description: The ID of the playbook instance to execute - name: inputs description: JSON Object of optional playbook inputs outputs: - contextPath: TaegisXDR.Execution description: The playbook execution ID type: string description: Executes a Taegis playbook instance execution: true - name: taegis-fetch-playbook-execution arguments: - name: id required: true description: Playbook execution ID outputs: - contextPath: TaegisXDR.PlaybookExecution description: Returns related execution information description: Fetch the results of a Taegis playbook instance execution - name: taegis-fetch-comment arguments: - name: id required: true description: The ID of the comment to fetch outputs: - contextPath: TaegisXDR.Comment description: Return the comment description: Fetch comment by comment ID - name: taegis-fetch-comments arguments: - name: parent_id required: true description: The ID of the parent related to the comments - name: parent_type description: The parent type that the comments belong to defaultValue: investigation outputs: - contextPath: TaegisXDR.Comments description: A list of comments to return description: Fetch comments by Parent Type and ID - name: taegis-create-comment arguments: - name: comment required: true description: The comment string to add to the parent - name: parent_id required: true description: The parent that the comment is being added to - name: parent_type description: The parent type that the comment is being added to defaultValue: investigation outputs: - contextPath: TaegisXDR.CommentCreate description: The created comment information description: Create a comment on an investigation - name: taegis-update-comment arguments: - name: id required: true description: The ID of the comment to update - name: comment required: true description: String to update/replace the comment with outputs: - contextPath: TaegisXDR.CommentUpdate description: The comment update results description: Update an existing comment - name: taegis-fetch-users arguments: - name: id description: The auth0 ID, in 'auth0|12345' format - name: email description: The email address to search for - name: status description: Search by user status - name: page description: Page for results defaultValue: "0" - name: page_size description: Results to return per page defaultValue: "10" outputs: - contextPath: TaegisXDR.Users description: The located user(s) description: Fetch a user by ID or email address - name: taegis-archive-investigation arguments: - name: id required: true description: ID of investigation to update outputs: - contextPath: TaegisXDR.ArchivedInvestigation description: The results from archiving an investigation description: Archive an investigation - name: taegis-unarchive-investigation arguments: - name: id required: true description: ID of investigation to update outputs: - contextPath: TaegisXDR.UnarchivedInvestigation description: The results from unarchiving an investigation description: Unarchive an investigation - name: taegis-update-alert-status arguments: - name: ids required: true description: A list of alert IDs or string of comma-separated alert IDs to return isArray: true - name: status required: true auto: PREDEFINED predefined: - FALSE_POSITIVE - NOT_ACTIONABLE - OPEN - TRUE_POSITIVE_BENIGN - TRUE_POSITIVE_MALICIOUS description: The status to update the alert with - name: reason description: A simple comment/reason for the status change outputs: - contextPath: TaegisXDR.AlertStatusUpdate description: The result of the alert status update description: Update the status of an alert - name: taegis-fetch-assets arguments: - name: page description: Search results page number defaultValue: "0" - name: page_size description: The number of results per-page defaultValue: "10" - name: endpoint_type description: Filter assets by asset type - name: host_id description: Filter assets by host ID - name: hostname description: Filter assets by hostname - name: investigation_id description: Filter assets by related investigation ID - name: ip_address description: Filter assets by IP address - name: mac_address description: Filter assets by MAC address - name: os_family description: Filter assets by OS family - name: os_version description: Filter assets by OS version - name: sensor_version description: Filter assets by sensor version - name: username description: Filter assets by username outputs: - contextPath: TaegisXDR.Assets description: A list of located assets description: Fetch assets based on search criteria - name: taegis-isolate-asset arguments: - name: id required: true description: Asset ID to isolate - name: reason required: true description: A reason for the isolation outputs: - contextPath: TaegisXDR.AssetIsolation description: Results from the asset isolation description: Isolate a specific asset - name: taegis-fetch-endpoint arguments: - name: id required: true description: The endpoint ID to fetch outputs: - contextPath: TaegisXDR.Endpoint description: Results from fetching the endpoint information description: Fetch endpoint information dockerimage: demisto/python3:3.10.12.65389 subtype: python3 isfetch: true isFetchSamples: true fromversion: 5.5.0 tests: - No tests (auto formatted)