SymantecEDR
Symantec EDR (On Prem) endpoints help to detect threats in your network by filter endpoints data to find Indicators of Compromise (IoCs) and take actions to remediate the threat(s). EDR on-premise capabilities allow incident responders to quickly search, identify, and contain all impacted endpoints while investigating threats using a choice of on-premises.
- Category
- Network Security
- Pack
- SymantecEDR
Configuration parameters
- url — Server URL (i.e., https://host:port) (required)
- credentials — Client ID (required)
- isFetch — Fetch incidents
- fetch_incidents_events_type — Incident data source
- isIncidentsEvent — Fetch incidents alerts
- isIncidentComment — Fetch incident comments
- fetch_status — Incidents "Status" to filter out fetching as incidents. Comma-separated lists are supported, e.g., Open, In-Progress
- fetch_priority — Incidents "Priority" to filter out fetching as incidents. Comma-separated lists are supported, e.g., Medium,High.
- fetch_event_status — Events "Status" to filter out fetching as incidents. Comma-separated lists are supported, e.g., Unknown, Success
- fetch_severity — Events "Severity" to filter out fetching as incidents. Comma-separated lists are supported, e.g., Info, Warning
- fetch_incidents_query — Query string to fetch incidents/events. For example - "updated:[2017-01-01T00:00:00.000Z TO 2017-01-08T00:00:00.000Z]"
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 10 minutes, 12 hours, 7 days)
- max_fetch — Maximum number of incidents to fetch
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- integration_reliability — Source Reliability
Commands (21)
- file — Issue a sandbox command of a specific SHA2.
- symantec-edr-allow-list-policy-get — Get allow list policies.
- symantec-edr-audit-event-list — Get audit events.
- symantec-edr-deny-list-policy-get — Get deny list policies.
- symantec-edr-domain-file-association-list — List of domain and file association.
- symantec-edr-domain-instance-list — Get domain instances.
- symantec-edr-endpoint-cancel-command — Cancel a command that is already in progress. Cancel the command execution on all the endpoints where it is still in progress. \nOnly one command can be cancelled at a time.
- symantec-edr-endpoint-delete-file — Deletes a file, i.e., deletes all instances of the file, based on the file hash that you have specified from the endpoint using the device ID.
- symantec-edr-endpoint-domain-association-list — List of endpoint and domain association.
- symantec-edr-endpoint-file-association-list — List of domain and file association.
- symantec-edr-endpoint-instance-list — Get endpoint instances.
- symantec-edr-endpoint-isolate — Isolates or quarantines endpoints by cutting connections that the endpoint(s) has to internal networks and external networks, based on the endpoint device IDs.
- symantec-edr-endpoint-rejoin — Rejoins endpoints by re-establishing connections that the endpoint(s) has to internal networks and external networks, based on the endpoint IDs.
- symantec-edr-endpoint-status — Get the command status.
- symantec-edr-event-list — Get events or system alerts from EDR on-premise.
- symantec-edr-file-instance-list — Get File Instances.
- symantec-edr-incident-comment-get — Get incident comments based on incident UUID.
- symantec-edr-incident-event-list — Get events for incidents.
- symantec-edr-incident-list — Get incidents from Symantec EDR on-premise API.
- symantec-edr-incident-update — Incidents patch command to close an incident, update the resolution of a closed incident, or add comments to the incident.
- symantec-edr-system-activity-list — Get system activities or logs.