Traps
Deprecated. Use CortexXDR instead.
- Category
- Endpoint
- Pack
- Traps
Configuration parameters
- url — Server URL (required)
- application_id — Application ID (required)
- private_key — Private Key (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (14)
- traps-endpoint-files-retrieve — Executes a file retrieve operation / SAM on the specified agent.
- traps-endpoint-files-retrieve-result — Returns the result of the endpoint file retrieve operation.
- traps-endpoint-isolate — Isolates the specified endpoint.
- traps-endpoint-isolate-status — Returns the status of the specified endpoint isolate operation.
- traps-endpoint-scan — Performs a scan operation on the specified endpoint.
- traps-endpoint-scan-result — Returns the results of an endpoint scan operation.
- traps-event-bulk-update-status — Modifies the status of multiple events.
- traps-event-quarantine — Creates a quarantine entry for the specified event.
- traps-event-quarantine-result — Returns the result of the specified quarantine operation.
- traps-event-update — Modifies the status and adds a comment to an existing event.
- traps-get-endpoint-by-id — Returns details for the specified endpoint.
- traps-hash-blacklist — Adds the specified file hash to the block list.
- traps-hash-blacklist-remove — Removes the specified file hash from the block list.
- traps-hashes-blacklist-status — Returns the block list status of the specified file hashes.