FireEye HX
Deprecated. Use FireEyeHX v2 instead.
- Category
- Endpoint
- Pack
- FireEyeHX
Configuration parameters
- server — Server URL (e.g. https://192.168.0.1:3000) (required)
- credentials — Credentials (required)
- version — Version (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- fetch_limit — Fetch limit
- incidentFetchInterval — Incidents Fetch Interval
Commands (19)
- fireeye-hx-append-conditions — Add conditions to an indicator. Conditions can be MD5, hash values, domain names and IP addresses.
- fireeye-hx-cancel-containment — Release a specific host from containment.
- fireeye-hx-create-indicator — Create new indicator.
- fireeye-hx-data-acquisition — Start a data acquisition process to gather artifacts from the system disk and memory. The data is fetched as mans file.
- fireeye-hx-delete-data-acquisition — Delete data acquisition.
- fireeye-hx-delete-file-acquisition — Delete the file acquisition, by ID.
- fireeye-hx-file-acquisition — Aquire a specific file as a password protected zip file. The password for unlocking the zip file is 'unzip-me'.
- fireeye-hx-get-alert — Get details of a specific alert.
- fireeye-hx-get-alerts — Get a list of alerts, use the different arguments to filter the results returned.
- fireeye-hx-get-all-hosts-information — Get information on all hosts.
- fireeye-hx-get-data-acquisition — Gather artifacts from the system disk and memory for the given acquisition id. The data is fetched as mans file.
- fireeye-hx-get-host-information — Get information on a host associated with an agent.
- fireeye-hx-get-host-set-information — Get a list of all host sets known to your HX Series appliance.
- fireeye-hx-get-indicator — Get a specific indicator details.
- fireeye-hx-get-indicators — Get a list of indicators.
- fireeye-hx-host-containment — Apply containment for a specific host, so that it no longer has access to other systems.
- fireeye-hx-initiate-data-acquisition — Initiate a data acquisition process to gather artifacts from the system disk and memory.
- fireeye-hx-search — Search endpoints to check all hosts or a subset of hosts for a specific file or indicator.
- fireeye-hx-suppress-alert — Suppress alert by ID.