GuardiCore v2
The GuardiCore v2 integration provides access to incident and endpoint (asset) information via the GuardiCore API.
- Category
- Deception & Breach Simulation
- Pack
- GuardiCore
Configuration parameters
- base_url — Server URL (required)
- credentials — Username (required)
- isFetch — Fetch incidents
- source — Source
- destination — Destination
- tag — Tag
- incident_type — Incident Type
- severity — Incident Severity
- max_fetch — Maximum incidents to fetch
- first_fetch — First fetch time
- timeout — Global timeout to all requests
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
Commands (4)
- endpoint — Gets information regarding endpoints.
- guardicore-get-incident — Display information about an incident.
- guardicore-get-incidents — Display information about incidents.
- guardicore-search-asset — Display information about assets.