McAfee Active Response
Connect to MAR using its DXL client.
- Category
- Endpoint
- Pack
- McAfee-MAR
Configuration parameters
- broker_ca_bundle — Broker CA certificates content (see `brokercerts.crt` in instructions) (required)
- cert_file — Client certificates content (see `client.crt` in instructions) (required)
- private_key — Client private key content (see `client.key` in instructions) (required)
- broker_urls — Brokers urls (comma separated list in the form of - [ssl://]<hostname>[:port]) - get hostname & port from `brokerlist.properties` file in instructions. Note that the broker should be reachable from demisto server (required)
Commands (11)
- mar-collectors-list — Returns a list of all collectors and their outputs
- mar-search — Search endpoint data
- mar-search-files — Gets files information from McAfee Active Response
- mar-search-host-info — Gets host information from McAfee Active Response
- mar-search-multiple — Search endpoint data crossed by multiple collectors
- mar-search-processes — Gets processes information from McAfee Active Response
- mar-search-scheduled-tasks — Gets scheduled tasks information from McAfee Active Response
- mar-search-services — Gets services information from McAfee Active Response
- mar-search-usb-connected-storage-devices — Gets Usb connected devices information from McAfee Active Response
- mar-search-user-profiles — Gets user profiles information from McAfee Active Response
- mar-search-win-registry — Gets WinRegistry information from McAfee Active Response