CounterTack
CounterTack empowers endpoint security teams to assure endpoint protection for Identifying Cyber Threats. Integrating a predictive endpoint protection platform.
- Category
- Endpoint
- Pack
- CounterTack
Configuration parameters
- server — Server URL (e.g. https://democloud.countertack.com) (required)
- credentials — User Name (required)
- proxy — Use system proxy settings
- unsecure — Trust any certificate (not secure)
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)
- fetch_notifications — Fetch notifications incidents
- fetch_behviors — Fetch behviors incidents
Commands (22)
- countertack-add-behavior-tags — Adds tags to a given behavior.
- countertack-add-tags — Adds tags to a given endpoint.
- countertack-delete-behavior-tags — Deletes the supplied tags from a given behavior.
- countertack-delete-file — Deletes a file from the given endpoint.
- countertack-delete-tags — Deletes the supplied tags from a given endpoint.
- countertack-disable-quarantine — Removes a given endpoint from quarantine.
- countertack-download-file — Downloads an extracted file in ZIP format. The password to unlock the ZIP file is `sentinel`.
- countertack-endpoint-quarantine — Quarantines a given endpoint.
- countertack-extract-file — Extracts a file from given endpoint.
- countertack-get-all-files — Gets all extracted files for all endpoints.
- countertack-get-behavior — Gets information of a given behavior.
- countertack-get-behaviors — Returns information for all behaviors.
- countertack-get-endpoint — Get information on specific endpoint
- countertack-get-endpoint-files — Returns all extracted files from a given endpoint.
- countertack-get-endpoint-tags — Gets the tags of a given endpoint.
- countertack-get-endpoints — Returns information for endpoints.
- countertack-get-file-information — Gets the information of a given file.
- countertack-kill-process — Terminates all instances of the process identified in the command. Processes can be identified by the PID or process name.
- countertack-search-behaviors — Request for behaviors search using CQL expression (Contextual Query Language) to represent queries.
- countertack-search-endpoints — Request for endpoints search using CQL expression (Contextual Query Language) to represent queries.
- countertack-search-events — Searches for events, using CQL expression.
- countertack-search-hashes — Searches for hashes using CQL expressions (Contextual Query Language) to represent queries.