GuardiCore
Deprecated. Use GuardiCore v2 instead.
- Category
- Deception & Breach Simulation
- Pack
- GuardiCore
Configuration parameters
- server — Server URL (e.g. https://192.168.0.1) (required)
- credentials — Username (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (13)
- guardicore-dns-requests — Display the DNS requests.
- guardicore-get-incident — Display information about the given incident.
- guardicore-get-incident-attachments — Retrieve the files attached to the given incidents.
- guardicore-get-incident-events — Display the events related to the given incidents.
- guardicore-get-incident-iocs — Display the IOCs (Indicators of Compromise) of the given incident.
- guardicore-get-incident-pcap — Retrieve the PCAP file attached to the given incident.
- guardicore-get-incidents — Display information about incidents (with filters).
- guardicore-misconfigurations — Display the misconfigurations.
- guardicore-search-endpoint — Display information about the endpoint by its hostname or IP address.
- guardicore-search-network-log — Searches within the network log (with filters).
- guardicore-show-endpoint — Display information about the endpoint given its ID.
- guardicore-uncommon-domains — Display the uncommon domains.
- guardicore-unresolved-domains — Display the unresolved domains.