MAR - Endpoint data collection
McAfee Active Response Pack.#
This Playbook is part of theUse McAfee Active Response to collect data from an endpoint for IR purposes (requires ePO as well).
Input:
- Hostname (Default: ${Endpoint.Hostname})
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- McAfee ePO v2
- McAfee Active Response
#
Scripts- Exists
#
Commands- mar-search-multiple
- epo-find-system
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
Hostname | Hostname to run on. | Endpoint.Hostname | Optional |
#
Playbook OutputsThere are no outputs for this playbook.