ForescoutEyeInspect
Delivers flexible and scalable OT/ICS asset visibility.
- Category
- Network Security
- Pack
- ForescoutEyeInspect
Configuration parameters
- server_url — Server URL (required)
- credentials — Username (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- max_fetch — Maximum incidents per fetch
- first_fetch — First fetch timestamp (<number> <time unit>, like 12 hours, 7 days).
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- isFetch — Fetch incidents
Commands (27)
- forescout-ei-alert-list — Retrieves information about the alerts inside eyeInspect CC.
- forescout-ei-alert-pcap-get — Retrieves the PCAP file associated to a given alert.
- forescout-ei-diagnostic-logs-get — Download the ZIP file that contains diagnostic logs of the Command Center.
- forescout-ei-diagnostics-information-get — Retrieves information about all monitored Command Center resources and their health status excluding the logs.
- forescout-ei-domain-blacklist-add — Adds a new entry to the domain name blacklist from the Industrial Threat Library of the specified sensor.
- forescout-ei-domain-blacklist-get — Retrieves the domain name blacklist from the Industrial Threat Library of the specified sensor.
- forescout-ei-file-operation-blacklist-add — Adds entries to the file operation blacklist from the Industrial Threat Library of the specified sensor.
- forescout-ei-file-operation-blacklist-get — Retrieves the file operation blacklist from the Industrial Threat Library of the specified sensor.
- forescout-ei-group-policy-create — Create a new group policy.
- forescout-ei-group-policy-delete — Delete a group policy.
- forescout-ei-group-policy-hosts-assign — Add all hosts not assigned to any policy (individual or group) matching the filter to the group policy.
- forescout-ei-group-policy-hosts-unassign — Unassign all hosts assigned to the group policy matching the filter.
- forescout-ei-group-policy-list — Get all group policies.
- forescout-ei-group-policy-update — Update a group policy. Note: Since the entire policy will be overridden, all fields are required.
- forescout-ei-host-list — Retrieves information about the hosts in the eyeInspect CC database.
- forescout-ei-hosts-changelog-list — Retrieves information about the changes of host properties and configuration from the eyeInspect CC database.
- forescout-ei-ip-blacklist-add — Adds a new entry to the IP blacklist from the Industrial Threat Library of the specified sensor.
- forescout-ei-ip-blacklist-get — Retrieves the IP blacklist from the Industrial Threat Library of the specified sensor.
- forescout-ei-ip-reuse-domain-list — Get all IP reuse domains.
- forescout-ei-link-list — Retrieves information about the links in the eyeInspect CC database.
- forescout-ei-sensor-list — Retrieves information about the sensors associated to the eyeInspect CC.
- forescout-ei-sensor-module-delete — Deletes the specified module from the specified sensor and from the eyeInspect CC database.
- forescout-ei-sensor-module-list — Retrieves information about the modules of the specified sensor.
- forescout-ei-sensor-module-update — Changes the specified properties of the specified module.
- forescout-ei-ssl-client-blacklist-add — Adds a new entry to the SSL client application blacklist from the Industrial Threat Library of the specified sensor.
- forescout-ei-ssl-client-blacklist-get — Retrieves the SSL client application blacklist from the Industrial Threat Library of the specified sensor.
- forescout-ei-vulnerability-info-get — Retrieves information about a specific vulnerability stored in the eyeInspect CC database.