Hurukai - Get Artifact RAM Dump

Get a RAM dump from Windows and Linux endpoints.

HarfangLab EDR · 7 tasks · 1 input · 0 outputs

Details

IDHurukai - Get Artifact RAM Dump
From Version6.2.0
Tasks7

README

Get a RAM dump from Windows and Linux endpoints.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • GenericPolling

Integrations

  • Hurukai

Scripts

This playbook does not use any scripts.

Commands

  • harfanglab-get-endpoint-info
  • harfanglab-result-artifact-ramdump
  • harfanglab-job-artifact-ramdump

Playbook Inputs


Name Description Default Value Required
agentid     Required

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Hurukai - Get Artifact RAM Dump

Inputs

  • agentid

Commands used

harfanglab-get-endpoint-info harfanglab-job-artifact-ramdump harfanglab-result-artifact-ramdump

Flowchart

windows/linux Start Start GenericPolling - GenericPolling GenericPolling GenericPolling Done Done harfanglab-job-artifact-ramdump - harfanglab-job-artifact-ramdump harfanglab-job-artifact-r... harfanglab-job-artifact-ramdump harfanglab-result-artifact-ramdump - harfanglab-result-artifact-ramdump harfanglab-result-artifac... harfanglab-result-artifact-ra... Which platform is the agent running on ? Which platform is the age... harfanglab-get-endpoint-info - harfanglab-get-endpoint-info harfanglab-get-endpoint-info harfanglab-get-endpoint-info
contentitemexportablefields:
  contentitemfields:
    propagationLabels:
    - all
description: Get a RAM dump from Windows and Linux endpoints.
id: Hurukai - Get Artifact RAM Dump
inputs:
- description: ''
  key: agentid
  playbookInputQuery:
  required: true
  value: {}
name: Hurukai - Get Artifact RAM Dump
outputs: []
starttaskid: '0'
tasks:
  '0':
    id: '0'
    ignoreworker: false
    isautoswitchedtoquietmode: false
    isoversize: false
    nexttasks:
      '#none#':
      - '9'
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ''
      id: 6e1c6d65-146d-4717-8b58-bf6c9db34312
      iscommand: false
      name: ''
      version: -1
      description: ''
    taskid: 6e1c6d65-146d-4717-8b58-bf6c9db34312
    timertriggers: []
    type: start
    view: |-
      {
        "position": {
          "x": 600,
          "y": -980
        }
      }
  '3':
    id: '3'
    ignoreworker: false
    isautoswitchedtoquietmode: false
    isoversize: false
    loop:
      exitCondition: ''
      iscommand: false
      max: 0
      wait: 1
    nexttasks:
      '#none#':
      - '7'
    note: false
    quietmode: 0
    scriptarguments:
      Ids:
        simple: ${Harfanglab.Job.ID}
      Interval:
        simple: '1'
      PollingCommandArgName:
        simple: ids
      PollingCommandName:
        simple: harfanglab-job-info
      Timeout:
        simple: '60'
      dt:
        simple: Harfanglab.Job.Info(val.Status !== 'finished').ID
    separatecontext: true
    skipunavailable: false
    task:
      brand: ''
      description: |-
        Use this playbook as a sub-playbook to block execution of the master playbook until a remote action is complete.
        This playbook implements polling by continuously running the command in Step \#2 until the operation completes.
        The remote action should have the following structure:

        1. Initiate the operation.
        2. Poll to check if the operation completed.
        3. (optional) Get the results of the operation.
      id: b321e3d1-1b36-4175-8b30-2344a5ac41ef
      iscommand: false
      name: GenericPolling
      playbookId: GenericPolling
      type: playbook
      version: -1
    taskid: b321e3d1-1b36-4175-8b30-2344a5ac41ef
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 700,
          "y": -260
        }
      }
  '5':
    id: '5'
    ignoreworker: false
    isautoswitchedtoquietmode: false
    isoversize: false
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ''
      id: 579ef529-3e91-49e8-8883-d121df821425
      iscommand: false
      name: Done
      type: title
      version: -1
      description: ''
    taskid: 579ef529-3e91-49e8-8883-d121df821425
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 550,
          "y": 100
        }
      }
  '6':
    id: '6'
    ignoreworker: false
    isautoswitchedtoquietmode: false
    isoversize: false
    nexttasks:
      '#none#':
      - '3'
    note: false
    quietmode: 0
    scriptarguments:
      agent_id:
        simple: ${inputs.agentid}
    separatecontext: false
    skipunavailable: false
    task:
      brand: Hurukai
      description: Start a job to get the entire RAM from a host (Windows / Linux)
      id: dbd59e2d-288a-44c2-8e99-73ddbd1e325b
      iscommand: true
      name: harfanglab-job-artifact-ramdump
      script: Hurukai|||harfanglab-job-artifact-ramdump
      type: regular
      version: -1
    taskid: dbd59e2d-288a-44c2-8e99-73ddbd1e325b
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 700,
          "y": -450
        }
      }
  '7':
    evidencedata:
      customfields: {}
      description:
        simple: Raw RAM dump file
    id: '7'
    ignoreworker: false
    isautoswitchedtoquietmode: false
    isoversize: false
    nexttasks:
      '#none#':
      - '5'
    note: false
    quietmode: 0
    scriptarguments:
      job_id:
        simple: ${Harfanglab.Job.ID}
    separatecontext: false
    skipunavailable: false
    task:
      brand: Hurukai
      description: Get a hostname's RAM dump from job results
      id: e9117369-a8cb-41d9-8863-a8c50cd2371a
      iscommand: true
      name: harfanglab-result-artifact-ramdump
      script: Hurukai|||harfanglab-result-artifact-ramdump
      type: regular
      version: -1
    taskid: e9117369-a8cb-41d9-8863-a8c50cd2371a
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 700,
          "y": -90
        }
      }
  '8':
    conditions:
    - condition:
      - - left:
            iscontext: true
            value:
              complex:
                accessor: Agent
                root: Harfanglab
                transformers:
                - args:
                    field:
                      value:
                        simple: ostype
                  operator: getField
          operator: isEqualString
          right:
            value:
              simple: windows
        - left:
            iscontext: true
            value:
              complex:
                accessor: Agent
                root: Harfanglab
                transformers:
                - args:
                    field:
                      value:
                        simple: ostype
                  operator: getField
          operator: isEqualString
          right:
            value:
              simple: linux
      label: windows/linux
    id: '8'
    ignoreworker: false
    isautoswitchedtoquietmode: false
    isoversize: false
    nexttasks:
      '#default#':
      - '5'
      windows/linux:
      - '6'
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ''
      id: d4f68e9d-475a-4008-8bd5-9b869e4f3a43
      iscommand: false
      name: Which platform is the agent running on ?
      type: condition
      version: -1
      description: ''
    taskid: d4f68e9d-475a-4008-8bd5-9b869e4f3a43
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 600,
          "y": -670
        }
      }
  '9':
    id: '9'
    ignoreworker: false
    isautoswitchedtoquietmode: false
    isoversize: false
    nexttasks:
      '#none#':
      - '8'
    note: false
    quietmode: 0
    scriptarguments:
      agent_id:
        simple: ${inputs.agentid}
    separatecontext: false
    skipunavailable: false
    task:
      brand: Hurukai
      description: Get endpoint information from agent_id
      id: f7bc2ebb-fd99-4bbc-88cb-525b1f5de0d5
      iscommand: true
      name: harfanglab-get-endpoint-info
      script: Hurukai|||harfanglab-get-endpoint-info
      type: regular
      version: -1
    taskid: f7bc2ebb-fd99-4bbc-88cb-525b1f5de0d5
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 600,
          "y": -845
        }
      }
version: -1
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 1145,
        "width": 530,
        "x": 550,
        "y": -980
      }
    }
  }
tests:
- No tests (auto formatted)
fromversion: 6.2.0