Closed rc-csmith closed 1 year ago
Implemented support for Cortex XDR:
cortex
To-Do Items
dataset=xdr_data <INSERT_PROVIDED_FILTERS> | fields agent_hostname, action_process_image_path, action_process_username, action_process_image_command_line, actor_process_image_path, actor_primary_username, actor_process_command_line, event_id
[PROFILE_NAME] url=https://url-to-api api_key=API_KEY_HERE api_key_id=API_KEY_ID_HERE auth_type=STANDARD_OR_ADVANCED tenant_id=OPTIONAL_LIST_OF_COMMA_SEPARATED_TENANT_IDS
Implemented support for Cortex XDR:
cortex
click command.To-Do Items
cortex
to hunt Cortex XDR product