DarktraceAdmin
This pack includes configurations to combine the world-class threat detection of Darktrace with the synchrony and automation abilities of XSOAR, allowing security teams to manage device actions including device statuses and tags. Your understanding of potential threats can also be levelled-up with Advanced Search logs from DPI.
- Category
- Network Security
- Pack
- Darktrace
Configuration parameters
- url — Server URL (e.g. https://example.net) (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- incidentType — Incident type
- publicApiKey — Public API Token (required)
- privateApiKey — Private API Token (required)
Commands (8)
- darktrace-get-device-connection-info — Returns the graphable data for a device (max of 4 weeks of connections retained).
- darktrace-get-external-endpoint-details — Returns details collected by Darktrace about external IP addresses or hostnames.
- darktrace-get-similar-devices — Returns a list of similar devices with respect to a specified device.
- darktrace-get-tagged-devices — Get all devices that hold a common tag.
- darktrace-get-tags-for-device — Get all tags for the given device.
- darktrace-post-tag-to-device — Post a tag to a device.
- darktrace-post-to-watched-list — Post to the list of Darkace Watched Domains to generate alerts when visited.
- darktrace-run-advanced-search-analysis — Run an Advanced Search Query and perform an analysis operation on any metric.