ArgusManagedDefence
Rapidly detect, analyse and respond to security threats with mnemonic’s leading Managed Detection and Response (MDR) service.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- mnemonicMDR
Configuration parameters
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- api_url — API URL (required)
- api_key — API Key (required)
- min_severity — Minimum severity of alerts to fetch (required)
- first_fetch — First fetch time
- max_fetch — Maximum number of incidents per fetch
- exclude_tag — Fetch incidents exclude tag
- mirror_direction — Incident Mirroring Direction
- mirror_tag — Mirroring tag
- close_argus_case — Close Argus Case
- close_incident — Close XSOAR Incident
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (35)
- argus-add-attachment — Add attachment to case (Max 50 MB, should be an archive).
- argus-add-case-tag — Adds a key, value tag to an Argus case.
- argus-add-comment — Add comment to an Argus case.
- argus-advanced-case-search — Returns cases matching the defined case search criteria.
- argus-close-case — Close an Argus case.
- argus-create-case — Create Argus case.
- argus-delete-case — Mark existing case as deleted.
- argus-delete-comment — Mark existing comment as deleted.
- argus-download-attachment — Download specific attachment contents.
- argus-download-attachment-by-filename — Downloads case attachment by best-effort search of filename.
- argus-download-case-attachments — Download all attachments related to Argus Case.
- argus-edit-comment — Edit existing comment.
- argus-fetch-observations-for-domain — Look up reputation observations for the given domain.
- argus-fetch-observations-for-ip — Look up reputation observations for the given IP.
- argus-find-aggregated-events — Search for aggregated events (OSB! advanced method: look in API doc).
- argus-find-nids-events — Search for NIDS events.
- argus-get-attachment — Fetch specific attachment metadata.
- argus-get-case-metadata-by-id — Returns the basic case descriptor for the case identified by ID.
- argus-get-event — Fetch specified event.
- argus-get-events-for-case — Fetch events associated with specified case.
- argus-get-payload — Fetch specified event payload.
- argus-get-pcap — Fetch specified event payload as PCAP.
- argus-list-aggregated-events — List aggregated events.
- argus-list-case-attachments — List attachments for an existing case.
- argus-list-case-comments — List the comments of an Argus case.
- argus-list-case-tags — List tags attached to an Argus case.
- argus-list-nids-events — Simple search for NIDS events.
- argus-pdns-search-records — Search against PassiveDNS with criteria and return matching records.
- argus-print-case-comments — Print case comments as notes.
- argus-print-case-metadata-by-id — Print case metadata as HTML. Does not add to context.
- argus-remove-case-tag-by-id — Remove existing tag by tag ID.
- argus-remove-case-tag-by-key-value — Remove existing tag with key, value matching.
- argus-update-case — Request changes to basic fields of an existing case.
- get-remote-data — Get remote data from a remote incident. This method does not update the current incident, and should be used for debugging purposes.
- update-remote-system — Updates the remote system with incident changes.