Hurukai
HarfangLab EDR Connector, Compatible version 2.13.7+.
- Category
- Endpoint
- Pack
- HarfangLabEDR
Configuration parameters
- url — API URL (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- credentials —
- apikey — API Key
- longRunning — Long running instance
- incidentFetchInterval — Incidents Fetch Interval
- alert_type — Fetch alerts with type
- min_severity — Minimum severity of alerts to fetch (required)
- alert_status — Fetch alerts with status (ACTIVE, CLOSED)
- max_fetch — Maximum number of incidents to fetch per call
- first_fetch — First fetch time (required)
- mirror_direction — Mirroring Direction
- fetch_types — Fetch types
- close_incident — Close Mirrored security event or threat in the XSOAR
- close_in_hfl — Close Mirrored security event or threat in HarfangLab EDR
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (77)
- fetch-incidents — Allows to retrieve incidents from the HarfangLab EDR API.
- get-mapping-fields — Returns the list of fields to map in outgoing mirroring. This command is only used for debugging purposes.
- get-modified-remote-data — Gets the list of security events and threats that were modified since the last update time. This method is used for debugging purposes. The get-modified-remote-data command is used as part of the Mirroring feature that was introduced in Cortex XSOAR version 6.1.
- get-remote-data — Gets remote data from a remote security event or threat. This method does not update the current security event or threat, and should be used for debugging purposes only.
- harfanglab-add-ioc-to-source — Add an IOC to a Threat Intelligence source.
- harfanglab-api-call — Perform a generic API call.
- harfanglab-assign-policy-to-agent — Assign a policy to an agent.
- harfanglab-change-security-event-status — Command used to change the status of a security event.
- harfanglab-deisolate-endpoint — Command used to deisolate an endpoint and reconnect it to the network.
- harfanglab-delete-ioc-from-source — Delete an IOC from a Threat Intelligence source.
- harfanglab-endpoint-search — Search for endpoint information from a hostname.
- harfanglab-get-endpoint-info — Get endpoint information from agent_id.
- harfanglab-hunt-search-hash — Command used to search a hash IOC in database.
- harfanglab-hunt-search-runned-process-hash — Command used to search runned process associated with Hash.
- harfanglab-hunt-search-running-process-hash — Command used to search running process associated with Hash.
- harfanglab-isolate-endpoint — Command used to isolate an endpoint from the network while remaining connected to the EDR manager.
- harfanglab-job-artifact-all — Start a job to download all artifacts from a host (Windows MFT, Hives, evt/evtx, Prefetch, USN, Linux logs and file list).
- harfanglab-job-artifact-downloadfile — Start a job to download a file from a host (Windows / Linux).
- harfanglab-job-artifact-evtx — Start a job to download the event logs from a host (Windows).
- harfanglab-job-artifact-filesystem — Start a job to download Linux filesystem entries from a host (Linux).
- harfanglab-job-artifact-hives — Start a job to download the hives from a host (Windows).
- harfanglab-job-artifact-logs — Start a job to download Linux log files from a host (Linux).
- harfanglab-job-artifact-mft — Start a job to download the MFT from a host (Windows).
- harfanglab-job-artifact-ramdump — Start a job to get the entire RAM from a host (Windows / Linux).
- harfanglab-job-driverlist — Start a job to get the list of drivers from a host (Windows).
- harfanglab-job-info — Get job status information.
- harfanglab-job-ioc — Start a job to search for IOCs on a host (Windows / Linux).
- harfanglab-job-networkconnectionlist — Start a job to get the list of network connections from a host (Windows / Linux).
- harfanglab-job-networksharelist — Start a job to get the list of network shares from a host (Windows).
- harfanglab-job-persistencelist — Start a job to get the list of persistence items from a host (Linux).
- harfanglab-job-pipelist — Start a job to get the list of pipes from a host (Windows).
- harfanglab-job-prefetchlist — Start a job to get the list of prefetches from a host (Windows).
- harfanglab-job-processlist — Start a job to get the list of processes from a host (Windows / Linux).
- harfanglab-job-runkeylist — Start a job to get the list of run keys from a host (Windows).
- harfanglab-job-scheduledtasklist — Start a job to get the list of scheduled tasks from a host (Windows).
- harfanglab-job-servicelist — Start a job to get the list of services from a host (Windows).
- harfanglab-job-sessionlist — Start a job to get the list of sessions from a host (Windows).
- harfanglab-job-startuplist — Start a job to get the list of startup items from a host (Windows).
- harfanglab-job-wmilist — Start a job to get the list of WMI items from a host (Windows).
- harfanglab-result-artifact-all — Get all artifacts from a hostname from job results.
- harfanglab-result-artifact-downloadfile — Get a hostname's file from job results.
- harfanglab-result-artifact-evtx — Get a hostname's log files from job results.
- harfanglab-result-artifact-filesystem — Get a hostname's filesystem entries from job results.
- harfanglab-result-artifact-hives — Get a hostname's hives from job results.
- harfanglab-result-artifact-logs — Get a hostname's log files from job results.
- harfanglab-result-artifact-mft — Get a hostname's MFT from job results.
- harfanglab-result-artifact-ramdump — Get a hostname's RAM dump from job results.
- harfanglab-result-driverlist — Get a hostname's loaded drivers from job results.
- harfanglab-result-ioc — Get the list of items matching IOCs searched in an IOC job.
- harfanglab-result-networkconnectionlist — Get a hostname's network connections from job results.
- harfanglab-result-networksharelist — Get a hostname's network shares from job results.
- harfanglab-result-persistencelist — Get a hostname's persistence items from job results.
- harfanglab-result-pipelist — Get a hostname's list of pipes from job results.
- harfanglab-result-prefetchlist — Get a hostname's list of prefetches from job results.
- harfanglab-result-processlist — Get a hostname's list of processes from job results.
- harfanglab-result-runkeylist — Get a hostname's list of run keys from job results.
- harfanglab-result-scheduledtasklist — Get a hostname's list of scheduled tasks from job results.
- harfanglab-result-servicelist — Get a hostname's list of services from job results.
- harfanglab-result-sessionlist — Get a hostname's sessions from job results.
- harfanglab-result-startuplist — Get a hostname's startup items from job results.
- harfanglab-result-wmilist — Get a hostname's WMI items from job results.
- harfanglab-telemetry-authentication-linux — Search Linux authentication telemetry.
- harfanglab-telemetry-authentication-macos — Search Macos authentication telemetry.
- harfanglab-telemetry-authentication-users — Get the top n users who successfully authenticated on the host.
- harfanglab-telemetry-authentication-windows — Search Windows authentication telemetry.
- harfanglab-telemetry-binary — Search for binaries.
- harfanglab-telemetry-dns — Search DNS resolutions.
- harfanglab-telemetry-eventlog — Search event logs.
- harfanglab-telemetry-network — Search network connections.
- harfanglab-telemetry-process-graph — Get a process graph.
- harfanglab-telemetry-processes — Search processes.
- harfanglab-whitelist-add — Add a whitelist.
- harfanglab-whitelist-add-criterion — Add a criterion to an existing whitelist.
- harfanglab-whitelist-delete — Delete a whitelist.
- harfanglab-whitelist-search — Search whitelists from a keyword.
- test-module — Allows to test that the HarfangLab EDR API is reachable.
- update-remote-system — Updates the remote security event or threat with local security event or threat changes. This method is only used for debugging purposes and will not update the current security event or threat.