Details

Built upon original Cisco Secure Endpoint - Find Computers to search by a SHA-256 hash and return a list of computers.

Description

Searches Cisco Secure Endpoint for computers by Hash. If no search options are provided, all computers will be returned.

Target: Secure Endpoint - v1 or an HTTP Endpoint for "api.amp.cisco.com" with a path of "/v1"

Account Key: None for Secure Endpoint - v1 or HTTP Basic Authentication for an HTTP Endpoint

Steps:
[] Build the relative URL
[] Search for matching computers
[] Check if the request was successful:
[]> If it was, attempt to extract the results and set the output variables
[]> If it wasn't, return an error

More information about this API can be found in Secure Endpoint's API documentation: https://developer.cisco.com/docs/secure-endpoint/v1-api-reference-computer/

About
Author
cpeters@sugarlandtx.gov
Version
v1.0
Integration
Average rating
No ratings yet
Authorship
Community
Contact and support information
External links
Related workflows
Cisco Managed
This incident response workflow allows you to add hashes involved in an incident to a simple custom detection list in Cisco Secure Endpoint through a playbook or using an automation rule.
Community
# Cisco Secure Endpoint Exclusion List Export Workflow The Workflow will list exclusion lists of Cisco Secure Endpoint for validating and review.
Community
This workflow will list duplicate GUIDs in Cisco Secure Endpoint for validation and review.
Cisco Managed
This incident response workflow fetches vulnerability information from Cisco Secure Endpoint for assets involved in an incident when triggered from a playbook or using an automation rule.
Cisco Managed
This workflow appears in the pivot menu and allows you to request approval to isolate a host using Cisco Secure Endpoint.
Cisco Managed
This incident response workflow allows you to isolate hosts involved in an incident using Cisco Secure Endpoint from a playbook or using an automation rule.
Cisco Managed
This workflow appears in the pivot menu and will move the endpoint identified by the provided observable to a device group in Cisco Secure Endpoint.
Cisco Managed
This incident response workflow allows you to move computers to a group in Cisco Secure Endpoint from a playbook or using an automation rule.