ZeroTrustAnalyticsPlatform
Zero Trust Analytics Platform (ZTAP) is the underlying investigation platform and user interface for Critical Start's MDR service.
- Category
- Endpoint
- Pack
- ZeroTrustAnalyticsPlatform
Configuration parameters
- url — ZTAP server URL (required)
- apikey — API Key (required)
- reopen_group — Reopen Group (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- mirror_direction — Incident Mirroring Direction
- comment_tag — Comment entry tag
- escalate_tag — Escalate entry tag
- input_tag — ZTAP input tag
- get_attachments — Fetch attachments for comments from ZTAP
- close_incident — Sync closing incidents with ZTAP
- reopen_incident — Sync reopening incidents with ZTAP
- first_fetch — First fetch timestamp
- max_fetch — Maximum number of incidents to fetch
Commands (3)
- get-mapping-fields — Get mapping fields from remote incident.
- get-remote-data — Get remote data from a remote incident. This command should only be called manually for debugging purposes.
- ztap-get-alert-entries — Get the entries data from a remote incident.