Copies a file from an entry to the destination path on the specified system. This uses the dissolvable agent's HTTPS communication channel rather than SCP or other out-of-band methods.
!CopyFileD2 destpath=/home/sansforensics/collectedbinaries/inv8_suspiciousPE1.exe.evil entryid=21@8 system=Analyst1
|The system to which we want to copy the file.
|The full filesystem path and filename under which to save the file.
|The ID of the War Room entry containing the file to copy.
|The overwrite file.
There are no outputs for this script.