Skip to main content

Illusive-Collect-Forensics-On-Demand

This Playbook is part of the Illusive Networks Pack.#

This playbook is used to collect forensics on-demand on any compromised host and retrieve the forensics timeline upon successful collection.

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

  • GenericPolling

Integrations#

  • IllusiveNetworks

Scripts#

  • Print

Commands#

  • illusive-run-forensics-on-demand
  • illusive-get-forensics-timeline
  • illusive-get-event-incident-id

Playbook Inputs#


NameDescriptionDefault ValueRequired
fqdn_or_ipThe host fqdn or IP address on which to collect forensicsRequired
start_dateThe starting date of the forensics timeline.
Optional
end_dateThe last date of the forensics timeline.
Optional

Playbook Outputs#


PathDescriptionType
Illusive.Forensics.Evidence.detailsThe forensics evidence detailsunknown
Illusive.Forensics.Evidence.eventIdThe event IDunknown
Illusive.Forensics.Evidence.idThe forensics evidence IDunknown
Illusive.Forensics.Evidence.sourceThe Evidence sourceunknown
Illusive.Forensics.Evidence.starredWhether the forensics evidence has been starredunknown
Illusive.Forensics.Evidence.timeDate and time of the forensics evidenceunknown
Illusive.Forensics.Evidence.titleThe forensics evidence descriptionunknown
Illusive.Forensics.IncidentIdThe Incident Idunknown

Playbook Image