FireEyeHX v2
FireEye Endpoint Security is an integrated solution that detects and protects endpoints against known and unknown threats. This integration provides access to information about endpoints, acquisitions, alerts, indicators, and containment. You can extract critical data and effectively operate the security operations automated playbook.
- Category
- Endpoint
- Pack
- FireEyeHX
Configuration parameters
- server — Server URL (e.g., https://192.168.0.1:3000) (required)
- userName — User Name (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- max_fetch — Fetch limit
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 3 days)
- incidentFetchInterval — Incidents Fetch Interval
Commands (42)
- fireeye-hx-append-conditions — Add conditions to an indicator. Conditions can be MD5, hash values, domain names, and IP addresses.
- fireeye-hx-approve-containment — Approves pending containment requests made by other components or users. The required permission is api_admin role.
- fireeye-hx-assign-host-set-policy — Inserts a new host set policy on your Endpoint Security server.
- fireeye-hx-cancel-containment — Releases a specific host from containment.
- fireeye-hx-create-host-set-dynamic — Creates a dynamic host set. To use this command you must have admin permissions.
- fireeye-hx-create-host-set-static — Creates a static host set. To use this command you must have admin permissions.
- fireeye-hx-create-indicator — Create a new indicator.
- fireeye-hx-data-acquisition — Start a data acquisition process to gather artifacts from the system disk and memory. The data is fetched as a MANS file.
- fireeye-hx-delete-data-acquisition — Deletes data acquisition.
- fireeye-hx-delete-file-acquisition — Deletes the file acquisition by ID.
- fireeye-hx-delete-host-set — Deletes a host set. To use this command you must have admin permissions.
- fireeye-hx-delete-host-set-policy — Deletes a Host Set policy.
- fireeye-hx-delete-indicator — Delete an indicator.
- fireeye-hx-delete-indicator-condition — Delete an indicator condition.
- fireeye-hx-file-acquisition — Acquires a specific file as a password protected zip file. The password for unlocking the zip file is 'unzip-me'.
- fireeye-hx-get-alert — Get details of a specific alert.
- fireeye-hx-get-alerts — Returns a list of alerts. Use the different arguments to filter the results returned.
- fireeye-hx-get-all-hosts-information — Returns information on all hosts.
- fireeye-hx-get-data-acquisition — Collects artifacts from the system disk and memory for the given acquisition ID. The data is fetched as a MANS file.
- fireeye-hx-get-host-information — Returns information on a host associated with an agent.
- fireeye-hx-get-host-set-information — Returns a list of all host sets known to your HX Series appliance.
- fireeye-hx-get-indicator — Get details of a specific indicator.
- fireeye-hx-get-indicators — Get a list of indicators.
- fireeye-hx-host-acquisitions-list — Gets all acquisitions for a host
- fireeye-hx-host-containment — Applies containment for a specific host, so that it no longer has access to other systems. If the user does not have the necessary permissions, the command will not approve the request. The permission required to approve the request is api_admin role.
- fireeye-hx-initiate-data-acquisition — Initiates a data acquisition process to collect artifacts from the system disk and memory.
- fireeye-hx-list-containment — Fetches all containment states across known hosts.
- fireeye-hx-list-host-set-policy — Returns a list of all policies for all host sets.
- fireeye-hx-list-indicator-category — Lists the indicator categories.
- fireeye-hx-list-policy — Returns a list of all policies.
- fireeye-hx-search — Searches endpoints to check all hosts or a subset of hosts for a specific file or indicator.
- fireeye-hx-search-delete — Deletes the search by ID.
- fireeye-hx-search-list — Fetches all enterprise searches.
- fireeye-hx-search-result-get — Fetches the results for a specific enterprise search.
- fireeye-hx-search-stop — Stops a specific running search.
- fireeye-hx-suppress-alert — Suppresses an alert by ID.
- fireeye-hx-triage-acquisition-delete — Deletes a triage acquisition.
- fireeye-hx-triage-acquisition-get — Gets information about a specified triage acquisition.
- fireeye-hx-triage-acquisition-package-get — Gets the triage acquisition package for the given acquisition ID.
- fireeye-hx-triage-acquisition-start — Starts a triage acquisition
- fireeye-hx-update-host-set-dynamic — Updates dynamic host set. To use this command you must have admin permissions.
- fireeye-hx-update-host-set-static — Updates a static host set. To use this command you must have admin permissions.