Code42
Use the Code42 integration to identify potential data exfiltration from insider threats while speeding investigation and response by providing fast access to file events and metadata across physical and cloud environments.
- Category
- Endpoint
- Pack
- Code42
Configuration parameters
- console_url — Code42 Console URL for your Code42 environment
- api_url — API Gateway URL for your Code42 environment (required)
- credentials — API Client ID (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- alert_severity — Alert severities to fetch when fetching incidents
- fetch_time — First fetch time range (<number> <time unit>, e.g., 1 hour, 30 minutes)
- fetch_limit — Alerts to fetch per run; note that increasing this value may result in slow performance if too many results are returned at once
- include_files — Include the list of files in returned incidents.
- incidentFetchInterval — Incidents Fetch Interval
Commands (20)
- code42-alert-get — Retrieve alert details by alert ID.
- code42-alert-resolve — DEPRECATED. Use code42-alert-update instead.
- code42-alert-update — Changes the state of an Incydr alert session.
- code42-download-file — Downloads a file from Code42.
- code42-download-file-by-xfc-id — Downloads a file from Incydr using the XFC Event ID.
- code42-file-events-search — Search for Code42 Incydr File Events.
- code42-file-events-table — Render Code42 file events from the context as a markdown table.
- code42-legalhold-add-user — Adds a Code42 user to a legal hold matter.
- code42-legalhold-remove-user — Removes a Code42 user from a legal hold matter.
- code42-user-block — DEPRECATED. Use the Incydr console to block users.
- code42-user-create — DEPRECATED. Use the Incydr console to create users.
- code42-user-deactivate — Deactivate a user in Code42; signing them out of their devices. Backups discontinue for a deactivated user, and their archives go to cold storage.
- code42-user-get-risk-profile — Get the risk profile details for a given user.
- code42-user-reactivate — Reactivates the user with the given username.
- code42-user-unblock — DEPRECATED. Use the Incydr console to unblock users.
- code42-user-update-risk-profile — Update a user's risk profile.
- code42-watchlists-add-user — Add a user to a watchlist.
- code42-watchlists-list — List all existing watchlists in your environment.
- code42-watchlists-list-included-users — List all users who have been explicitly added to a given watchlist.
- code42-watchlists-remove-user — Remove a user from a watchlist.