Illusive-Collect-Forensics-On-Demand

This playbook is used to collect forensics on-demand on any compromised host and retrieve the forensics timeline upon successful collection.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • GenericPolling

Integrations

  • IllusiveNetworks

Scripts

  • Print

Commands

  • illusive-run-forensics-on-demand
  • illusive-get-forensics-timeline
  • illusive-get-event-incident-id

Playbook Inputs


NameDescriptionDefault ValueRequired
fqdn_or_ipThe host fqdn or IP address on which to collect forensicsRequired
start_dateThe starting date of the forensics timeline.
Optional
end_dateThe last date of the forensics timeline.
Optional

Playbook Outputs


PathDescriptionType
Illusive.Forensics.Evidence.detailsThe forensics evidence detailsunknown
Illusive.Forensics.Evidence.eventIdThe event IDunknown
Illusive.Forensics.Evidence.idThe forensics evidence IDunknown
Illusive.Forensics.Evidence.sourceThe Evidence sourceunknown
Illusive.Forensics.Evidence.starredWhether the forensics evidence has been starredunknown
Illusive.Forensics.Evidence.timeDate and time of the forensics evidenceunknown
Illusive.Forensics.Evidence.titleThe forensics evidence descriptionunknown
Illusive.Forensics.IncidentIdThe Incident Idunknown