Skip to main content

Get host forensics - Generic

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

This playbook retrieves forensics from hosts. The available integration is Illusive networks.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

Illusive-Collect-Forensics-On-Demand

Integrations#

This playbook does not use any integrations.

Scripts#

IsIntegrationAvailable

Commands#

This playbook does not use any commands.

Playbook Inputs#


NameDescriptionDefault ValueRequired
fqdn_or_ipIf using illusive integration to retrieve additional forensics, provide fqdn_or_ip of the host from which to get the forensics.Optional
start_dateDate_range must be "number date_range_unit", examples: (2 hours, 4 minutes,6 months, 1 day, etc.)Optional
end_dateDate_range must be "number date_range_unit", examples: (2 hours, 4 minutes,6 months, 1 day, etc.)Optional

Playbook Outputs#


There are no outputs for this playbook.

Playbook Image#


Get host forensics - Generic