MAR - Endpoint data collection
McAfee Active Response Pack.#
This Playbook is part of theCollects data using McAfee Active Response, from an endpoint for IR purposes (requires ePO as well).
Input:
- Hostname (Default: ${Endpoint.Hostname})
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- McAfee Active Response
- McAfee ePO v2
#
Scripts- Exists
- EPOFindSystem
#
Commands- mar-search-multiple
- epo-find-system
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
Hostname | The hostname to run on. | ${Endpoint.Hostname} | Optional |
#
Playbook OutputsThere are no outputs for this playbook.