IllusiveNetworks
The Illusive Attack Management API allows customers to retrieve detected incidents with a forensics timeline, attack surface insights, collect forensics on-demand, and manage a variety of operations with regard to deceptive entities, deception policies, and more.
- Category
- Deception & Breach Simulation
- Pack
- IllusiveNetworks
Configuration parameters
- url — Server URL (e.g. https://example.net) (required)
- api_token — API Token (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- fetch_time — The initial time to fetch from
- has_forensics — Fetch only incidents with forensics
Commands (20)
- illusive-add-deceptive-servers — Add or approve deceptive servers.
- illusive-add-deceptive-users — Add or approve deceptive users.
- illusive-assign-host-to-policy — Assign a deception policy to domain hosts.
- illusive-delete-deceptive-servers — Delete deceptive servers.
- illusive-delete-deceptive-users — Delete deceptive users.
- illusive-get-asm-cj-insight — Retrieve Crown-Jewels insights from Attack Surface Manager.
- illusive-get-asm-host-insight — Retrieve the specified host insights from Attack Surface Manager.
- illusive-get-deceptive-servers — Retrieve a list of all deceptive servers.
- illusive-get-deceptive-users — Retrieve a list of all deceptive users.
- illusive-get-event-incident-id — Retrieve the incident ID of an event.
- illusive-get-forensics-analyzers — Retrieve Illusive's forensics analyzers on a certain event.
- illusive-get-forensics-artifacts — Retrieve forensics artifacts from Illusive's forensics.
- illusive-get-forensics-timeline — Retrieve forensics timeline for a specific incident.
- illusive-get-forensics-triggering-process-info — Retrieve the triggering process information from Illusive's forensics.
- illusive-get-incident-events — Retrieve all the events that are associated with an incident.
- illusive-get-incidents — Retrieve incidents.
- illusive-is-deceptive-server — Retrieve whether a specified server is deceptive.
- illusive-is-deceptive-user — Retrieve whether a specified user is deceptive.
- illusive-remove-host-from-policy — Remove deception policy assignment from domain hosts.
- illusive-run-forensics-on-demand — Collect forensics on a specified host and retrieve the forensics timeline.