ExtraHop v2
ExtraHop Reveal(x) for Cortex XSOAR is a network detection and response solution that provides complete visibility of network communications at enterprise scale, real-time threat detections backed by machine learning, and guided investigation workflows that simplify response.
- Category
- Network Security
- Pack
- ExtraHop
Configuration parameters
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- on_cloud — On Cloud
- url — URL (required)
- apikey — API Key
- client_id — Client ID
- client_secret — Client Secret
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- first_fetch — First fetch time
- max_fetch — How many incidents to fetch each time
- advanced_filter — Advanced Filter
Commands (30)
- extrahop-activity-map-get — Get a link to a live activity map in ExtraHop Reveal(x).
- extrahop-alert-rule-create — Create a new alert rule in ExtraHop Reveal(x).
- extrahop-alert-rule-edit — Modify an alert rule in ExtraHop Reveal(x).
- extrahop-alert-rules-get — Get all alert rules from ExtraHop Reveal(x).
- extrahop-create-alert — Use extrahop-alert-rule-create instead. Create a new alert rule in Reveal(x).
- extrahop-create-alert-rule — Use extrahop-alert-rule-create instead. Create a new alert rule in Reveal(x).
- extrahop-detections-list — Get detections from ExtraHop Reveal(x).
- extrahop-device-search — Use extrahop-devices-search instead. Search for devices in Reveal(x).
- extrahop-devices-search — Search for devices in ExtraHop Reveal(x).
- extrahop-devices-tag — Add or remove a tag from devices in ExtraHop Reveal(x).
- extrahop-edit-alert — Use extrahop-alert-rule-edit instead. Modify an alert rule in Reveal(x).
- extrahop-edit-alert-rule — Use extrahop-alert-rule-edit instead. Modify an alert rule in Reveal(x).
- extrahop-edit-watchlist — Use extrahop-watchlist-edit instead. Add or remove devices from the watchlist in Reveal(x).
- extrahop-get-activity-map — Use extrahop-activity-map-get instead. Get a link to a live activity map in Reveal(x).
- extrahop-get-alert-rules — Use extrahop-alert-rules-get instead. Get all alert rules from Reveal(x).
- extrahop-get-alerts — Use extrahop-alert-rules-get instead. Get all alert rules from Reveal(x).
- extrahop-get-peers — Use extrahop-peers-get instead. Get all peers for a device from Reveal(x).
- extrahop-get-protocols — Use extrahop-protocols-get instead. Get all active network protocols for a device from Reveal(x).
- extrahop-get-watchlist — Use extrahop-watchlist-get instead. Get all devices on the watchlist in Reveal(x).
- extrahop-metrics-list — Get metrics for specified objects from ExtraHop Reveal(x).
- extrahop-packets-search — Search for specific packets in ExtraHop Reveal(x).
- extrahop-peers-get — Get all peers for a device from ExtraHop Reveal(x).
- extrahop-protocols-get — Get all active network protocols for a device from ExtraHop Reveal(x).
- extrahop-query-records — No available replacement. Query records from Reveal(x).
- extrahop-search-packets — Use extrahop-packets-search instead. Search for specific packets in Reveal(x).
- extrahop-tag-devices — Use extrahop-devices-tag instead. Add or remove a tag from devices in Reveal(x).
- extrahop-ticket-track — Link an ExtraHop Reveal(x) detection to a Cortex XSOAR incident.
- extrahop-track-ticket — Use extrahop-ticket-track instead. Link a Reveal(x) detection to a Demisto Investigation.
- extrahop-watchlist-edit — Add or remove devices from the advanced analysis watchlist in ExtraHop Reveal(x).
- extrahop-watchlist-get — Get all devices on the advanced analysis watchlist in ExtraHop Reveal(x).