FireEyeHelix
FireEye Helix is a security operations platform. FireEye Helix integrates security tools and augments them with next-generation SIEM, orchestration and threat intelligence tools such as alert management, search, analysis, investigations and reporting.
- Category
- Analytics & SIEM
- Pack
- FireEyeHelix
Configuration parameters
- url — Server URL (e.g. https://apps.fireeye.com) (required)
- h_id — Customer ID
- token — API Token
- h_id_creds — Customer ID
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (24)
- fireeye-helix-add-list-item — Adds an item to a list.
- fireeye-helix-alert-create-note — Creates an alert note.
- fireeye-helix-alert-delete-note — Deletes an alert note.
- fireeye-helix-alert-get-notes — Returns all notes related to an alert.
- fireeye-helix-archive-search — Creates an archive search from a query.
- fireeye-helix-archive-search-get-results — Fetches archive search results.
- fireeye-helix-archive-search-get-status — Gets the status of an archive search.
- fireeye-helix-create-list — Creates a list.
- fireeye-helix-delete-list — Deletes a single list by list ID.
- fireeye-helix-edit-rule — Modifies an existing rule.
- fireeye-helix-get-alert-by-id — Returns alert details, by alert ID.
- fireeye-helix-get-cases-by-alert — Returns cases of an alert.
- fireeye-helix-get-endpoints-by-alert — Retrieves a specific alert from an helix endpoint.
- fireeye-helix-get-events-by-alert — Lists alert events for a specific alert.
- fireeye-helix-get-list-by-id — Returns a specific list by list ID.
- fireeye-helix-get-list-items — Fetches items of a list.
- fireeye-helix-get-lists — Returns lists.
- fireeye-helix-list-alerts — Returns all alerts.
- fireeye-helix-list-rules — Returns all rules.
- fireeye-helix-list-sensors — Fetches all sensors.
- fireeye-helix-remove-list-item — Removes an item from a list.
- fireeye-helix-search — Executes a search in FireEye Helix using MQL.
- fireeye-helix-update-list — Updates an existing list.
- fireeye-helix-update-list-item — Updates a single list item.