category: Endpoint provider: Trellix commonfields: id: FireEye HX version: -1 configuration: - display: Server URL (e.g. https://192.168.0.1:3000) name: server required: true type: 0 - display: Credentials name: credentials required: true type: 9 - defaultvalue: v3 display: Version name: version required: true type: 0 - defaultvalue: 'false' display: Trust any certificate (not secure) name: insecure type: 8 required: false - defaultvalue: 'false' display: Use system proxy settings name: proxy type: 8 required: false - display: Fetch incidents name: isFetch type: 8 required: false - display: Incident type name: incidentType type: 13 required: false - defaultvalue: '100' display: Fetch limit name: fetch_limit type: 0 required: false - defaultvalue: '1' display: Incidents Fetch Interval name: incidentFetchInterval type: 19 required: false description: Deprecated. Use FireEyeHX v2 instead. display: FireEye HX (Deprecated) name: FireEye HX script: commands: - arguments: - description: The host name to be contained. If the hostName is not specified, the agentId must be specified. name: hostName - description: The agent id running on the host to be contained. If the agentId is not specified, the hostName must be specified. name: agentId description: Apply containment for a specific host, so that it no longer has access to other systems. name: fireeye-hx-host-containment outputs: - contextPath: FireEyeHX.Hosts._id description: FireEye HX Agent ID. type: Unknown - contextPath: FireEyeHX.Hosts.agent_version description: The agent version. type: Unknown - contextPath: FireEyeHX.Hosts.excluded_from_containment description: Determines whether the host is excluded from containment. type: Unknown - contextPath: FireEyeHX.Hosts.containment_missing_software description: Boolean value to indicate for containment missing software. type: Unknown - contextPath: FireEyeHX.Hosts.containment_queued description: Determines whether the host is queued for containment. type: Unknown - contextPath: FireEyeHX.Hosts.containment_state description: The containment state of the host. Possible values normal|contain|contain_fail|containing|contained|uncontain|uncontaining|wtfc|wtfu. type: Unknown - contextPath: FireEyeHX.Hosts.stats.alerting_conditions description: The number of conditions that have alerted for the host. type: Unknown - contextPath: FireEyeHX.Hosts.stats.alerts description: Total number of alerts, including exploit-detection alerts. type: Unknown - contextPath: FireEyeHX.Hosts.stats.exploit_blocks description: The number of blocked exploits on the host. type: Unknown - contextPath: FireEyeHX.Hosts.stats.malware_alerts description: The number of malware alerts associated with the host. type: Unknown - contextPath: FireEyeHX.Hosts.hostname description: The host name. type: Unknown - contextPath: FireEyeHX.Hosts.domain description: Domain name. type: Unknown - contextPath: FireEyeHX.Hosts.timezone description: Host time zone. type: Unknown - contextPath: FireEyeHX.Hosts.primary_ip_address description: The host IP address. type: Unknown - contextPath: FireEyeHX.Hosts.last_poll_timestamp description: The timestamp of the last system poll preformed on the host. type: Unknown - contextPath: FireEyeHX.Hosts.initial_agent_checkin description: Timestamp of the initial agent check-in. type: Unknown - contextPath: FireEyeHX.Hosts.last_alert_timestamp description: The time stamp of the last alert for the host. type: Unknown - contextPath: FireEyeHX.Hosts.last_exploit_block_timestamp description: Time when the last exploit was blocked on the host. The value is null if no exploits have been blocked. type: Unknown - contextPath: FireEyeHX.Hosts.os.product_name description: Specific operating system. type: Unknown - contextPath: FireEyeHX.Hosts.os.bitness description: OS Bitness. type: Unknown - contextPath: FireEyeHX.Hosts.os.platform description: Family of operating systems. Valid values are win, osx, and linux. type: Unknown - contextPath: FireEyeHX.Hosts.primary_mac description: The host MAC address. type: Unknown deprecated: true - arguments: - description: The host name to be contained. If the hostName is not specified, the agentId must be specified. name: hostName - description: The agent id running on the host to be contained. If the agentId is not specified, the hostName must be specified. name: agentId description: Release a specific host from containment. name: fireeye-hx-cancel-containment outputs: - contextPath: FireEyeHX.Hosts._id description: FireEye HX Agent ID. type: Unknown - contextPath: FireEyeHX.Hosts.agent_version description: The agent version. type: Unknown - contextPath: FireEyeHX.Hosts.excluded_from_containment description: Determines whether the host is excluded from containment. type: Unknown - contextPath: FireEyeHX.Hosts.containment_missing_software description: Boolean value to indicate for containment missing software. type: Unknown - contextPath: FireEyeHX.Hosts.containment_queued description: Determines whether the host is queued for containment. type: Unknown - contextPath: FireEyeHX.Hosts.containment_state description: The containment state of the host. Possible values normal|contain|contain_fail|containing|contained|uncontain|uncontaining|wtfc|wtfu. type: Unknown - contextPath: FireEyeHX.Hosts.stats.alerting_conditions description: The number of conditions that have alerted for the host. type: Unknown - contextPath: FireEyeHX.Hosts.stats.alerts description: Total number of alerts, including exploit-detection alerts. type: Unknown - contextPath: FireEyeHX.Hosts.stats.exploit_blocks description: The number of blocked exploits on the host. type: Unknown - contextPath: FireEyeHX.Hosts.stats.malware_alerts description: The number of malware alerts associated with the host. type: Unknown - contextPath: FireEyeHX.Hosts.hostname description: The host name. type: Unknown - contextPath: FireEyeHX.Hosts.domain description: Domain name. type: Unknown - contextPath: FireEyeHX.Hosts.timezone description: Host time zone. type: Unknown - contextPath: FireEyeHX.Hosts.primary_ip_address description: The host IP address. type: Unknown - contextPath: FireEyeHX.Hosts.last_poll_timestamp description: The timestamp of the last system poll preformed on the host. type: Unknown - contextPath: FireEyeHX.Hosts.initial_agent_checkin description: Timestamp of the initial agent check-in. type: Unknown - contextPath: FireEyeHX.Hosts.last_alert_timestamp description: The time stamp of the last alert for the host. type: Unknown - contextPath: FireEyeHX.Hosts.last_exploit_block_timestamp description: Time when the last exploit was blocked on the host. The value is null if no exploits have been blocked. type: Unknown - contextPath: FireEyeHX.Hosts.os.product_name description: Specific operating system. type: Unknown - contextPath: FireEyeHX.Hosts.os.bitness description: OS Bitness. type: Unknown - contextPath: FireEyeHX.Hosts.os.platform description: Family of operating systems. Valid values are win, osx, and linux. type: Unknown - contextPath: FireEyeHX.Hosts.primary_mac description: The host MAC address. type: Unknown deprecated: true compliantpolicies: - EndPoint Isolation - arguments: - auto: PREDEFINED description: Identifies which alerts result from indicators with the specified share mode. name: hasShareMode predefined: - any - restricted - unrestricted - auto: PREDEFINED description: Sorts the results by the specified field. name: resolution predefined: - active_threat - alert - block - partial_block - description: Filter by the agent ID. name: agentId - description: Filter by condition ID. name: conditionId - description: Filter event occurred time. ISO-8601 timestamp.. name: eventAt - description: Filter by alert ID. name: alertId - description: Filter by match detection time. ISO-8601 timestamp. name: matchedAt - description: Filter that returns only records with an AlertId field value great than the minId value. name: minId - description: Filter by reported time. ISO-8601 timestamp. name: reportedAt - auto: PREDEFINED description: Source of alert- indicator of compromise. name: IOCsource predefined: - yes - auto: PREDEFINED description: Source of alert - exploit detection. name: EXDsource predefined: - yes - auto: PREDEFINED description: Source of alert - malware alert. name: MALsource predefined: - yes - description: Limit the results returned. name: limit - auto: PREDEFINED description: Sorts the results by the specified field in ascending order. name: sort predefined: - agentId - conditionId - eventAt - alertId - matchedAt - id - reportedAt - auto: PREDEFINED description: The sort order for the results. name: sortOrder predefined: - ascending - descending description: Get a list of alerts, use the different arguments to filter the results returned. name: fireeye-hx-get-alerts outputs: - contextPath: FireEyeHX.Alerts._id description: FireEye alert ID. type: Unknown - contextPath: FireEyeHX.Alerts.agent._id description: FireEye agent ID. type: Unknown - contextPath: FireEyeHX.Alerts.agent.containment_state description: Host containment state. type: Unknown - contextPath: FireEyeHX.Alerts.condition._id description: The condition unique ID. type: Unknown - contextPath: FireEyeHX.Alerts.event_at description: Time when the event occoured. type: Unknown - contextPath: FireEyeHX.Alerts.matched_at description: Time when the event was matched. type: Unknown - contextPath: FireEyeHX.Alerts.reported_at description: Time when the event was reported. type: Unknown - contextPath: FireEyeHX.Alerts.source description: Source of alert. type: Unknown - contextPath: FireEyeHX.Alerts.matched_source_alerts._id description: Source alert ID. type: Unknown - contextPath: FireEyeHX.Alerts.matched_source_alerts.appliance_id description: Appliance ID. type: Unknown - contextPath: FireEyeHX.Alerts.matched_source_alerts.meta description: Source alert meta. type: Unknown - contextPath: FireEyeHX.Alerts.matched_source_alerts.indicator_id description: Indicator ID. type: Unknown - contextPath: FireEyeHX.Alerts.resolution description: Alert resulotion. type: Unknown - contextPath: FireEyeHX.Alerts.event_type description: Event type. type: Unknown deprecated: true - arguments: - description: The alert ID. The alert ID is listed in the output of 'get-alerts' command. name: alertId description: Suppress alert by ID. name: fireeye-hx-suppress-alert deprecated: true - arguments: - description: The indicator category. name: category - description: The searchTerm can be any name, category, signature, source, or condition value. name: searchTerm - auto: PREDEFINED description: Determines who can see the indicator. You must belong to the correct authorization group . name: shareMode predefined: - any - restricted - unrestricted - visible - auto: PREDEFINED description: Sorts the results by the specified field in ascending order. name: sort predefined: - category - activeSince - createdBy - alerted - description: Person who created the indicator. name: createdBy - auto: PREDEFINED description: Whether the indicator resulted in alerts. name: alerted predefined: - yes - no - description: Limit the number of results. name: limit description: Get a list of indicators. name: fireeye-hx-get-indicators outputs: - contextPath: FireEyeHX.Indicators._id description: FireEye unique indicator ID. type: Unknown - contextPath: FireEyeHX.Indicators.name description: The indicator name as displayed in the UI. type: Unknown - contextPath: FireEyeHX.Indicators.description description: Indicator description. type: Unknown - contextPath: FireEyeHX.Indicators.category.name description: Catagory name. type: Unknown - contextPath: FireEyeHX.Indicators.created_by description: The "Created By" field as displayed in UI. type: Unknown - contextPath: FireEyeHX.Indicators.active_since description: Date indicator became active. type: Unknown - contextPath: FireEyeHX.Indicators.stats.source_alerts description: Total number of source alerts associated with this indicator. type: Unknown - contextPath: FireEyeHX.Indicators.stats.alerted_agents description: Total number of agents with HX alerts associated with this indicator. type: Unknown - contextPath: FireEyeHX.Indicators.platforms description: List of families of operating systems. type: Unknown - contextPath: FireEyeHX.Indicators.uri_name description: URI formatted name of the indicator. type: String - contextPath: FireEyeHX.Indicators.category.uri_name description: URI name of the category. type: String deprecated: true - arguments: - description: Indicator category. Please use the `uri_category` value. name: category required: true - description: Indicator name. Please use the `uri_name` value. name: name required: true description: Get a specific indicator details. name: fireeye-hx-get-indicator outputs: - contextPath: FireEyeHX.Indicators._id description: FireEye unique indicator ID. type: Unknown - contextPath: FireEyeHX.Indicators.name description: The indicator name as displayed in the UI. type: Unknown - contextPath: FireEyeHX.Indicators.description description: Indicator description. type: Unknown - contextPath: FireEyeHX.Indicators.category.name description: Catagory name. type: Unknown - contextPath: FireEyeHX.Indicators.created_by description: The "Created By" field as displayed in UI. type: Unknown - contextPath: FireEyeHX.Indicators.active_since description: Date indicator became active. type: Unknown - contextPath: FireEyeHX.Indicators.stats.source_alerts description: Total number of source alerts associated with this indicator. type: Unknown - contextPath: FireEyeHX.Indicators.stats.alerted_agents description: Total number of agents with HX alerts associated with this indicator. type: Unknown - contextPath: FireEyeHX.Indicators.platforms description: List of families of operating systems. type: Unknown - contextPath: FireEyeHX.Conditions._id description: FireEye unique condition ID. type: Unknown - contextPath: FireEyeHX.Conditions.event_type description: Event type. type: Unknown - contextPath: FireEyeHX.Conditions.enabled description: Indicates whether the condition is enabled. type: Unknown deprecated: true - arguments: - description: The agent ID. If the agent ID is not specified, the host Name must be specified. name: agentId - description: The host name. If the host name is not specified, the agent ID must be specified. name: hostName description: Get information on a host associated with an agent. name: fireeye-hx-get-host-information outputs: - contextPath: FireEyeHX.Hosts._id description: FireEye HX Agent ID. type: Unknown - contextPath: FireEyeHX.Hosts.agent_version description: The agent version. type: Unknown - contextPath: FireEyeHX.Hosts.excluded_from_containment description: Determines whether the host is excluded from containment. type: Unknown - contextPath: FireEyeHX.Hosts.containment_missing_software description: Boolean value to indicate for containment missing software. type: Unknown - contextPath: FireEyeHX.Hosts.containment_queued description: Determines whether the host is queued for containment. type: Unknown - contextPath: FireEyeHX.Hosts.containment_state description: The containment state of the host. Possible values normal|contain|contain_fail|containing|contained|uncontain|uncontaining|wtfc|wtfu. type: Unknown - contextPath: FireEyeHX.Hosts.stats.alerting_conditions description: The number of conditions that have alerted for the host. type: Unknown - contextPath: FireEyeHX.Hosts.stats.alerts description: Total number of alerts, including exploit-detection alerts. type: Unknown - contextPath: FireEyeHX.Hosts.stats.exploit_blocks description: The number of blocked exploits on the host. type: Unknown - contextPath: FireEyeHX.Hosts.stats.malware_alerts description: The number of malware alerts associated with the host. type: Unknown - contextPath: FireEyeHX.Hosts.hostname description: The host name. type: Unknown - contextPath: FireEyeHX.Hosts.domain description: Domain name. type: Unknown - contextPath: FireEyeHX.Hosts.timezone description: Host time zone. type: Unknown - contextPath: FireEyeHX.Hosts.primary_ip_address description: The host IP address. type: Unknown - contextPath: FireEyeHX.Hosts.last_poll_timestamp description: The timestamp of the last system poll preformed on the host. type: Unknown - contextPath: FireEyeHX.Hosts.initial_agent_checkin description: Timestamp of the initial agent check-in. type: Unknown - contextPath: FireEyeHX.Hosts.last_alert_timestamp description: The time stamp of the last alert for the host. type: Unknown - contextPath: FireEyeHX.Hosts.last_exploit_block_timestamp description: Time when the last exploit was blocked on the host. The value is null if no exploits have been blocked. type: Unknown - contextPath: FireEyeHX.Hosts.os.product_name description: Specific operating system. type: Unknown - contextPath: FireEyeHX.Hosts.os.bitness description: OS Bitness. type: Unknown - contextPath: FireEyeHX.Hosts.os.platform description: Family of operating systems. Valid values are win, osx, and linux. type: Unknown - contextPath: FireEyeHX.Hosts.primary_mac description: The host MAC address. type: Unknown deprecated: true - arguments: - description: The alert ID. name: alertId required: true description: Get details of a specific alert. name: fireeye-hx-get-alert outputs: - contextPath: FireEyeHX.Alerts._id description: FireEye alert ID. type: Unknown - contextPath: FireEyeHX.Alerts.agent._id description: FireEye agent ID. type: Unknown - contextPath: FireEyeHX.Alerts.agent.containment_state description: Host containment state. type: Unknown - contextPath: FireEyeHX.Alerts.condition._id description: The condition unique ID. type: Unknown - contextPath: FireEyeHX.Alerts.event_at description: Time when the event occoured. type: Unknown - contextPath: FireEyeHX.Alerts.matched_at description: Time when the event was matched. type: Unknown - contextPath: FireEyeHX.Alerts.reported_at description: Time when the event was reported. type: Unknown - contextPath: FireEyeHX.Alerts.source description: Source of alert. type: Unknown - contextPath: FireEyeHX.Alerts.matched_source_alerts._id description: Source alert ID. type: Unknown - contextPath: FireEyeHX.Alerts.matched_source_alerts.appliance_id description: Appliance ID. type: Unknown - contextPath: FireEyeHX.Alerts.matched_source_alerts.meta description: Source alert meta. type: Unknown - contextPath: FireEyeHX.Alerts.matched_source_alerts.indicator_id description: Indicator ID. type: Unknown - contextPath: FireEyeHX.Alerts.resolution description: Alert resulotion. type: Unknown - contextPath: FireEyeHX.Alerts.event_type description: Event type. type: Unknown deprecated: true - arguments: - description: The file name. name: fileName required: true - description: The file path. name: filePath required: true - auto: PREDEFINED description: Whether to aqcuire the file using the API or RAW. By default, a raw file will be acquired. Use the API option when the file is encrypted. name: acquireUsing predefined: - API - RAW - description: The agent ID associated with the host that holds the file. If the hostName is not specified, the agentId must be specified. name: agentId - description: The host that holds the file. If the agentId is not specified, hostName must be specified. name: hostName description: Aquire a specific file as a password protected zip file. The password for unlocking the zip file is 'unzip-me'. name: fireeye-hx-file-acquisition outputs: - contextPath: FireEyeHX.Acquisitions.Files._id description: The acquisition unique ID. type: Unknown - contextPath: FireEyeHX.Acquisitions.Files.state description: The acquisition state. type: Unknown - contextPath: FireEyeHX.Acquisitions.Files.md5 description: File md5. type: Unknown - contextPath: FireEyeHX.Acquisitions.Files.req_filename description: The file name. type: Unknown - contextPath: FireEyeHX.Acquisitions.Files.req_path description: The file path. type: Unknown - contextPath: FireEyeHX.Acquisitions.Files.host._id description: FireEye HX agent ID. type: Unknown deprecated: true - arguments: - description: The acquisition ID. name: acquisitionId required: true description: Delete the file acquisition, by ID. name: fireeye-hx-delete-file-acquisition deprecated: true - arguments: - description: Acquisition script in JSON format. name: script - description: The script name. If the Acquisition script is specified, the script name must be specified as well. name: scriptName - auto: PREDEFINED description: Use default script. Select the host system. name: defaultSystemScript predefined: - osx - win - linux - description: The agent ID. If the host name is not specified, the agent ID must be specified. name: agentId - description: The host name. If the agent ID is not specified, the host name must be specified. name: hostName description: Start a data acquisition process to gather artifacts from the system disk and memory. The data is fetched as mans file. name: fireeye-hx-data-acquisition outputs: - contextPath: FireEyeHX.Acquisitions.Data._id description: The acquisition unique ID. type: Unknown - contextPath: FireEyeHX.Acquisitions.Data.state description: The acquisition state. type: Unknown - contextPath: FireEyeHX.Acquisitions.Data.md5 description: File md5. type: Unknown - contextPath: FireEyeHX.Acquisitions.Data.finish_time description: Time when the acquisition was finished. type: Unknown - contextPath: FireEyeHX.Acquisitions.Data.host._id description: Agent ID. deprecated: true - arguments: - description: The acquisition ID. name: acquisitionId required: true description: Delete data acquisition. name: fireeye-hx-delete-data-acquisition deprecated: true - arguments: - description: IDs of agents to be searched. name: agentsIds - description: Names of hosts to be searched. name: hostsNames - description: Id of host set to be searched. name: hostSet - description: Limit results count (once limit is reached, the search is stopped). name: limit - auto: PREDEFINED defaultValue: yes description: Should search be exhaustive or quick. name: exhaustive predefined: - yes - no - description: A valid IPv4 address to search for. name: ipAddress - auto: PREDEFINED description: Which operator to apply to the given IP address. name: ipAddressOperator predefined: - equals - not equals - description: A 32-character MD5 hash value to search for. name: fileMD5Hash - auto: PREDEFINED description: Which operator to apply to the given MD5 hash. name: fileMD5HashOperator predefined: - equals - not equals - description: Full path of file to search. name: fileFullPath - auto: PREDEFINED description: Which operator to apply to the given file path. name: fileFullPathOperator predefined: - equals - not equals - contains - not contains - description: DNS value to search for. name: dnsHostname - auto: PREDEFINED description: Which operator to apply to the given DNS. name: dnsHostnameOperator predefined: - equals - not equals - contains - not contains - auto: PREDEFINED description: Method by which search should be stopped after finding number of results. name: stopSearch predefined: - stopAndDelete - stop description: Search endpoints to check all hosts or a subset of hosts for a specific file or indicator. name: fireeye-hx-search outputs: - contextPath: FireEyeHX.Search.Results.Timestamp - Modified description: Time when the entry was last modified. type: string - contextPath: FireEyeHX.Search.Results.File Text Written description: The file text content. type: string - contextPath: FireEyeHX.Search.Results.File Name description: Name of the file. type: string - contextPath: FireEyeHX.Search.Results.File Full Path description: The full path of the file. type: string - contextPath: FireEyeHX.Search.Results.File Bytes Written description: Number of bytes written to the file. type: string - contextPath: FireEyeHX.Search.Results.Size in bytes description: Size of the file in bytes. type: string - contextPath: FireEyeHX.Search.Results.Browser Version description: Version of the browser. type: string - contextPath: FireEyeHX.Search.Results.Browser Name description: Name of the browser. type: string - contextPath: FireEyeHX.Search.Results.Cookie Name description: Name of the cookie. type: string - contextPath: FireEyeHX.Search.Results.DNS Hostname description: Name of the DNS host. type: string - contextPath: FireEyeHX.Search.Results.URL description: The event URL. type: string - contextPath: FireEyeHX.Search.Results.Username description: The event username. type: string - contextPath: FireEyeHX.Search.Results.File MD5 Hash description: MD5 hash of the file. type: string - contextPath: FireEyeHX.Search.HostID description: ID of the host. type: string - contextPath: FireEyeHX.Search.HostName description: Name of host. type: string - contextPath: FireEyeHX.Search.HostUrl description: Inner FireEye host url. type: string - contextPath: FireEyeHX.Search.SearchID description: ID of performed search. type: string - contextPath: FireEyeHX.Search.Results.Timestamp - Accessed description: Last accessed time. type: string - contextPath: FireEyeHX.Search.Results.Port description: Port. type: number - contextPath: FireEyeHX.Search.Results.Process ID description: ID of the process. type: string - contextPath: FireEyeHX.Search.Results.Local IP Address description: Local IP Address. type: string - contextPath: FireEyeHX.Search.Results.Local IP Address description: Local IP Address. type: string - contextPath: FireEyeHX.Search.Results.Local Port description: Local Port. type: number - contextPath: FireEyeHX.Search.Results.Username description: Username. type: string - contextPath: FireEyeHX.Search.Results.Remote Port description: Remote Port. type: number - contextPath: FireEyeHX.Search.Results.IP Address description: IP Address. type: string - contextPath: FireEyeHX.Search.Results.Process Name description: Process Name. type: string - contextPath: FireEyeHX.Search.Results.Timestamp - Event description: Timestamp - Event. type: string - contextPath: FireEyeHX.Search.Results.type description: The type of the event. type: string - contextPath: FireEyeHX.Search.Results.id description: ID of the result. type: string deprecated: true - arguments: - description: ID of a specific host set to get. name: hostSetID - description: Specifies which record to start with in the response. The offset value must be an unsigned 32-bit integer. The default is 0. name: offset - description: Specifies how many records are returned. The limit value must be an unsigned 32-bit integer. The default is 50. name: limit - description: Searches the names of all host sets connected to the specified HX appliance. name: search - description: Sorts the results by the specified field in ascending or descending order. The default is sorting by name in ascending order. Sortable fields are _id (host set ID) and name (host set name). name: sort - description: Specifies the name of host set to look for. name: name - description: Specifies the type of host sets to search for. name: type description: Get a list of all host sets known to your HX Series appliance. name: fireeye-hx-get-host-set-information outputs: - contextPath: FireEyeHX.HostSets._id description: host set id. type: number - contextPath: FireEyeHX.HostSets._revision description: Revision number. type: string - contextPath: FireEyeHX.HostSets.name description: Host set name. type: string - contextPath: FireEyeHX.HostSets.type description: Host set type (static/dynamic/hidden). type: string - contextPath: FireEyeHX.HostSets.url description: Host set FireEye url. type: string deprecated: true - arguments: - description: The indicator category. name: category required: true description: Create new indicator. name: fireeye-hx-create-indicator outputs: - contextPath: FireEyeHX.Indicators.active_since description: Date indicator became active. type: date - contextPath: FireEyeHX.Indicators.meta description: Meta data for new indicator. type: string - contextPath: FireEyeHX.Indicators.display_name description: The indicator display name. type: string - contextPath: FireEyeHX.Indicators.name description: The indicator name as displayed in the UI. type: string - contextPath: FireEyeHX.Indicators.created_by description: The "Created By" field as displayed in UI. type: string - contextPath: FireEyeHX.Indicators.url description: The data URL. type: string - contextPath: FireEyeHX.Indicators.create_text description: The indicator create text. type: Unknown - contextPath: FireEyeHX.Indicators.platforms description: List of families of operating systems. type: string - contextPath: FireEyeHX.Indicators.create_actor._id description: The ID of the actor. type: number - contextPath: FireEyeHX.Indicators.create_actor.username description: Actor user name. type: string - contextPath: FireEyeHX.Indicators.signature description: 'Signature of indicator.' type: string - contextPath: FireEyeHX.Indicators._revision description: Indicator revision. type: string - contextPath: FireEyeHX.Indicators._id description: FireEye unique indicator ID. type: string - contextPath: FireEyeHX.Indicator.description description: Indicator description. type: string - contextPath: FireEyeHX.Indicators.category._id description: Category ID. type: number - contextPath: FireEyeHX.Indicators.category.name description: Category name. type: string - contextPath: FireEyeHX.Indicators.category.share_mode description: Category share mode. type: string - contextPath: FireEyeHX.Indicators.category.uri_name description: Category uri name. type: string - contextPath: FireEyeHX.Indicators.category.url description: Category URL. type: string - contextPath: FireEyeHX.Indicators.uri_name description: The indicator uri name. type: string - contextPath: FireEyeHX.Indicators.stats.active_conditions description: Indicator active conditions. type: number - contextPath: FireEyeHX.Indicators.stats.alerted_agents description: Total number of agents with HX alerts associated with this indicator. type: number - contextPath: FireEyeHX.Indicators.stats.source_alerts description: Total number of source alerts associated with this indicator. type: number - contextPath: FireEyeHX.Indicators.update_actor._id description: Update actor ID. type: number - contextPath: FireEyeHX.Indicators.update_actor.username description: Update actor name. type: string deprecated: true - arguments: - description: The indicator category. Please use the `uri_category` value. name: category required: true - description: The name of the indicator. Please use the `uri_name` value. name: name required: true - description: 'A list of conditions to add. The list can include a list of IPv4 addresses, MD5 files, and domain names. For example: example.netexample.orgexample.lol' name: condition required: true description: Add conditions to an indicator. Conditions can be MD5, hash values, domain names and IP addresses. name: fireeye-hx-append-conditions deprecated: true - arguments: [] description: Get information on all hosts. name: fireeye-hx-get-all-hosts-information outputs: - contextPath: FireEyeHX.Hosts._id description: FireEye HX Agent ID. type: Unknown - contextPath: FireEyeHX.Hosts.agent_version description: The agent version. type: Unknown - contextPath: FireEyeHX.Hosts.excluded_from_containment description: Determines whether the host is excluded from containment. type: Unknown - contextPath: FireEyeHX.Hosts.containment_missing_software description: Boolean value to indicate for containment missing software. type: Unknown - contextPath: FireEyeHX.Hosts.containment_queued description: Determines whether the host is queued for containment. type: Unknown - contextPath: FireEyeHX.Hosts.containment_state description: The containment state of the host. Possible values normal|contain|contain_fail|containing|contained|uncontain|uncontaining|wtfc|wtfu. type: Unknown - contextPath: FireEyeHX.Hosts.stats.alerting_conditions description: The number of conditions that have alerted for the host. type: Unknown - contextPath: FireEyeHX.Hosts.stats.alerts description: Total number of alerts, including exploit-detection alerts. type: Unknown - contextPath: FireEyeHX.Hosts.stats.exploit_blocks description: The number of blocked exploits on the host. type: Unknown - contextPath: FireEyeHX.Hosts.stats.malware_alerts description: The number of malware alerts associated with the host. type: Unknown - contextPath: FireEyeHX.Hosts.hostname description: The host name. type: Unknown - contextPath: FireEyeHX.Hosts.domain description: Domain name. type: Unknown - contextPath: FireEyeHX.Hosts.timezone description: Host time zone. type: Unknown - contextPath: FireEyeHX.Hosts.primary_ip_address description: The host IP address. type: Unknown - contextPath: FireEyeHX.Hosts.last_poll_timestamp description: The timestamp of the last system poll preformed on the host. type: Unknown - contextPath: FireEyeHX.Hosts.initial_agent_checkin description: Timestamp of the initial agent check-in. type: Unknown - contextPath: FireEyeHX.Hosts.last_alert_timestamp description: The time stamp of the last alert for the host. type: Unknown - contextPath: FireEyeHX.Hosts.last_exploit_block_timestamp description: Time when the last exploit was blocked on the host. The value is null if no exploits have been blocked. type: Unknown - contextPath: FireEyeHX.Hosts.os.product_name description: Specific operating system. type: Unknown - contextPath: FireEyeHX.Hosts.os.bitness description: OS Bitness. type: Unknown - contextPath: FireEyeHX.Hosts.os.platform description: Family of operating systems. Valid values are win, osx, and linux. type: Unknown - contextPath: FireEyeHX.Hosts.primary_mac description: The host MAC address. type: Unknown deprecated: true - arguments: - description: Acquisition script in JSON format. name: script - description: The script name. If the Acquisition script is specified, the script name must be specified as well. name: scriptName - auto: PREDEFINED description: Use default script. Select the host system. name: defaultSystemScript predefined: - osx - win - linux - description: The agent ID. If the host name is not specified, the agent ID must be specified. name: agentId - description: The host name. If the agent ID is not specified, the host name must be specified. name: hostName description: Initiate a data acquisition process to gather artifacts from the system disk and memory. name: fireeye-hx-initiate-data-acquisition outputs: - contextPath: FireEyeHX.Acquisitions.Data._id description: The acquisition unique ID. type: string - contextPath: FireEyeHX.Acquisitions.Data.state description: The acquisition state. type: string - contextPath: FireEyeHX.Acquisitions.Data.md5 description: File md5. type: string - contextPath: FireEyeHX.Acquisitions.Data.host._id description: Agent ID. type: string - contextPath: FireEyeHX.Acquisitions.Data.host.hostname description: Hostname. type: string - contextPath: FireEyeHX.Acquisitions.Data.instance description: FIreEye HX instance. type: string - contextPath: FireEyeHX.Acquisitions.Data.finish_time description: Time when the acquisition finished. type: date deprecated: true - arguments: - description: The acquisition unique ID. name: acquisitionId required: true description: Gather artifacts from the system disk and memory for the given acquisition id. The data is fetched as mans file. name: fireeye-hx-get-data-acquisition outputs: - contextPath: FireEyeHX.Acquisitions.Data._id description: The acquisition unique ID. type: string - contextPath: FireEyeHX.Acquisitions.Data.state description: The acquisition state. type: string - contextPath: FireEyeHX.Acquisitions.Data.md5 description: File md5. type: string - contextPath: FireEyeHX.Acquisitions.Data.host._id description: Agent ID. type: string - contextPath: FireEyeHX.Acquisitions.Data.finish_time description: Time when the acquisition finished. type: string - contextPath: FireEyeHX.Acquisitions.Data.host.hostname description: Hostname. type: string - contextPath: FireEyeHX.Acquisitions.Data.instance description: FIreEye HX instance. type: date deprecated: true dockerimage: demisto/python3:3.12.8.3296088 isfetch: true script: '' subtype: python3 type: python fromversion: 5.0.0 tests: - No tests (deprecated) deprecated: true