TaegisXDR
Deprecated. Use TaegisXDR v2 instead.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- SecureWorks
Configuration parameters
- environment — Taegis Environment (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- client_id — Client ID (required)
- client_secret — Client Secret (required)
- isFetch — Fetch incidents
- max_fetch — Maximum number of incidents per fetch
- first_fetch — First fetch time interval
- incidentFetchInterval — Incidents Fetch Interval
- incidentType — Incident type
- include_assets — Include Assets in Fetch
Commands (18)
- taegis-archive-investigation — Archive an investigation
- taegis-create-comment — Create a comment on an investigation
- taegis-create-investigation — Create an Investigation within Taegis
- taegis-execute-playbook — Executes a Taegis playbook instance
- taegis-fetch-alerts — List Taegis alerts by ID
- taegis-fetch-assets — Fetch assets based on search criteria
- taegis-fetch-comment — Fetch comment by comment ID
- taegis-fetch-comments — Fetch comments by Parent Type and ID
- taegis-fetch-endpoint — Fetch endpoint information
- taegis-fetch-investigation — Fetch all investigations or a specific investigation
- taegis-fetch-investigation-alerts — Fetch Alert IDs related to a specific investigation
- taegis-fetch-playbook-execution — Fetch the results of a Taegis playbook instance execution
- taegis-fetch-users — Fetch a user by ID or email address
- taegis-isolate-asset — Isolate a specific asset
- taegis-unarchive-investigation — Unarchive an investigation
- taegis-update-alert-status — Update the status of an alert
- taegis-update-comment — Update an existing comment
- taegis-update-investigation — Update an existing investigation