Fidelis EDR
Use the Fidelis Endpoint integration for advanced endpoint detection and response (EDR) across Windows, Mac and Linux OSes for faster threat remediation.
- Category
- Endpoint
- Pack
- FidelisEndpoint
Configuration parameters
- url — Server URL (e.g. https://abcde.fideliscloud.com/) (required)
- credentials — Username (required)
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- isFetch — Fetch incidents
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)
- fetch_limit — Fetch limit (minimum 5)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (24)
- fidelis-endpoint-delete-file — Deletes a file at the specified path.
- fidelis-endpoint-delete-file-search-job — Removes the job to free up space on the server.
- fidelis-endpoint-execute-script — Executes a script package from Fidelis endpoint packages.
- fidelis-endpoint-file-search — Searches for files on multiple hosts, using file hash, file extension, file size, and other search criteria.
- fidelis-endpoint-file-search-result-metadata — Gets the job results metadata. The maximum is 50 results.
- fidelis-endpoint-file-search-status — Gets the file search job status.
- fidelis-endpoint-get-file — Gets the file stream and download the file.
- fidelis-endpoint-get-script-manifest — Gets the script manifest.
- fidelis-endpoint-get-script-result — Gets script job results.
- fidelis-endpoint-host-info — Searches for endpoints based on an IP address or hostname.
- fidelis-endpoint-isolate-network — Quarantines an endpoint. While isolated, the endpoint's network communication is restricted to only the allowed servers.
- fidelis-endpoint-kill-process — Terminates the process that matches the required parameter's process ID.
- fidelis-endpoint-list-alerts — Returns all alerts in the system.
- fidelis-endpoint-list-processes — Gets a list all processes according to the OS system.
- fidelis-endpoint-list-scripts — Gets a list of all script packages.
- fidelis-endpoint-query-by-dns — Queries by DNS request.
- fidelis-endpoint-query-connection-by-remote-ip — Queries a connection by remote IP address.
- fidelis-endpoint-query-dns-by-server-ip — Queries DNS by server IP address.
- fidelis-endpoint-query-dns-by-source-ip — Queries DNS by source IP address.
- fidelis-endpoint-query-events — Queries events.
- fidelis-endpoint-query-file — Queries a file by file hash.
- fidelis-endpoint-query-process — Query process.
- fidelis-endpoint-remove-network-isolation — Removes the endpoint from isolation.
- fidelis-endpoint-script-job-status — Gets the script execution status.