Covalence Managed Security
Triggers by triaged alerts from endpoint, cloud, and network security monitoring. Contains event details and easy-to-follow mitigation steps.
- Category
- Endpoint
- Pack
- CovalenceManagedSecurity
Configuration parameters
- credentials — Credentials (required)
- proxy — Use system proxy settings
- first_run_time_range — First run time range
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- isFetch — Fetch incidents
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- max_fetch — Fetch Limit
- broker_url — Broker Server URL
Commands (12)
- cov-mgsec-broker-cloud-action-by-aro — Broker - Cloud Action By ARO.
- cov-mgsec-broker-endpoint-action-by-aro — Broker - Endpoint Action By ARO.
- cov-mgsec-broker-endpoint-action-by-host — Broker - Endpoint Action By Host.
- cov-mgsec-broker-list-org — Broker - List organizations.
- cov-mgsec-broker-ping — Broker - Test connectivity to the Broker service.
- cov-mgsec-comment-aro — Comment on an ARO.
- cov-mgsec-get-aro — Query FES Portal for ARO.
- cov-mgsec-list-escalation-contacts — Get the escalation contact list for a given organization.
- cov-mgsec-list-key-contacts — Get the key contact list for a given organization.
- cov-mgsec-list-language — Get the default language for a given organization.
- cov-mgsec-list-org — List organizations.
- cov-mgsec-transition-aro — Transition an ARO.