Darktrace
Deprecated. Use DarktraceMBs, DarktraceAIA, DarktraceAdmin instead.
- Category
- Network Security
- Pack
- Darktrace
Configuration parameters
- url — Server URL (e.g. https://example.net) (required)
- isFetch — Fetch incidents
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- incidentType — Incident type
- public_creds —
- private_creds —
- min_score — Minimum Score (required)
- max_fetch — Maximum Model Breaches per Fetch
- first_fetch — First fetch time
- public_api_token — Public API Token (Deprecated)
- private_api_token — Private API Token (Deprecated)
Commands (12)
- darktrace-acknowledge — Acknowledge a model breach as specified by Model Breach ID
- darktrace-get-breach — Darktrace-get-breach returns a model breach based on its model breach id (pbid)
- darktrace-get-breach-details — Retrieve additional details on a modelbreach
- darktrace-get-comments — Returns the comments on a model breach based on its model breach id (pbid)
- darktrace-get-component — Get details of a component given the CID
- darktrace-get-device-connection-info — Returns the graphable data used in the "Connections Data" view for a specific device that can be accessed from the Threat Visualizer omnisearch in Darktrace. Data returned covers a 4 week period. Parameters are further documented at https://customerportal.darktrace.com/product-guides/main/api-deviceinfo-request. It is recommended to run the command to check the relevant fields in context.
- darktrace-get-device-identity-info — Gets device identity information based on label, tag, type, hostname, ip, mac, vendor and os. It is recommended to run the command to check the relevant fields in context.
- darktrace-get-entity-details — Returns a time sorted list of connections and events for a device or an entity such as a user credential.
- darktrace-get-external-endpoint-details — Returns details collected by Darktrace about external IP addresses or hostnames.
- darktrace-get-model — Get the details of a model given the UUID
- darktrace-list-similar-devices — Returns a list of similar devices to a device specified by Darktrace DID
- darktrace-unacknowledge — Unacknowledges a model breach as specified by Model Breach ID