Qodex.ai
Qodex.ai
Introduction
1-Secure Endpoint
Initialize Variables
Initialize: Set Variables
Check Status
Check Status
APIv1 - queries-Audit Logs
All Audit Log TypesAudit Log Type - AllowList
APIv1 - queries-Computers
Search computer by name and store additional valuesSearch computer by IPSpecific computer by GUID Trajectory
APIv1 - queries-Computer Activity (Hunting)-Query for Sightings
Which computer reported URL (Demo data)
APIv1 - queries-Computer Activity (Hunting)-Investigate
Computer ObjectGroup ObjectComputer Trajectory
APIv1 - queries-Endpoint Isolation
Isolation feature availability for endpointIsolation status for endpointIsolation StartIsolation Stop
APIv1 - queries-Events and Event Types-Events Per Computer
Event Type: Behavioral Protection for specific computer
APIv1 - queries-Events and Event Types
All Event TypesComputer Events by SHA256
APIv1 - queries-File List
Show Application Blocking List by nameShow all Simple Custom Detection Lists by name
APIv1 - queries-Forensic Snapshot (Hunting)
List Forensic Snapshots for Computer
APIv1 - queries-Indicators (Hunting)
List all available indicators with Event Count
APIv1 - queries-Vulnerabilities (Hunting)
Vulnerable Applications by GroupGUIDOS Vulnerabilities per ComputerVulnerable Applications by SHA256 and Computers
APIv1 - queries-Compromise Inbox (Hunting)
Compromises - Inbox
APIv1 - queries-Manage ORG-Event Streams
List Event StreamsList Event Stream by ID
APIv1 - queries-Manage ORG-Webhooks
List WebhooksDelete Webhook by ID
APIv1 - queries-Deployment Packages
Create Deployment packageCreate Deployment package Copy
Use Cases-Create and Delete Groups demo
Refill Sub-Group GUID if missing4-Generate Sub-Group5-Move Sub-Group under Top Group6-Delete Top group by GUID7-Delete Sub-group by GUID
APIv3 - queries-1-Generate Bearer Token first
APIv3 Generate Security Cloud API Access TokenAPIv3 Generate SE API Access TokenAPIv3 Access Secure Endpoint API - multiple ORGs
APIv3 - queries-Exclusions
List Exclusion Set Entries - WindowsList Cisco Maintained ExlcusionsCreate Exclusion ListList Exclusion List Property by GUIDChange Exclusion List Property by GUID (Name)Delete Exclusion List
APIv3 - queries-Device Control-DVC: List all configurations
List Device Control Configurations - ALL
APIv3 - queries-Device Control-DVC: Check if configuration exists
DVC: Check BaseRule and update variableDVC: Check exception rule is already there
APIv3 - queries-Device Control-DVC: Add configuration and exeption rule
1-Add a DVC ConfigurationAdd DVC Rule to given DVC configurationList DVC Rulses for given DVC configuration
APIv3 - queries-Device Control-DVC: remove configuration
1a-Update DVC ConfigurationRemove a DVC exeption ruleRemove a DVC Configuration
APIv3 - queries-IOCs
List IOCs
APIv3 - queries-Policies
List all Policy Objects (Search Parameters)List all Policy Types (dynamic Visualizer)Delete Policy Object
APIv3 - queries-Uninstall the connector
Uninstall the connector
APIv3 - queries-Firewall-FW: List all configurations
List Host Firewall Configurations
APIv3 - queries-Firewall-FW Get Host Firewall Configuration Properties by GUID
Get Host Firewall Configuration Properties by GUID
APIv3 - queries-Firewall-FW: List Firewall Configuration Rules
List Firewall Configuratin Rules
APIv3 - queries-Firewall-FW: Get Firewall Rule Details
Get Firewall Rule Details
APIv3 - queries-Firewall-FW: Create/Rename/Delete Firewall Configuration
Create Firewall ConfigurationUpdate Firewall Configuration - Default Action BlockDelete Firewall Configuration
APIv3 - queries-Firewall-FW: Create/Delete Firewall Rule
Create Firewall RuleDelete Firewall Rule
APIv3 - queries-Firewall-FW: My personal FW Test Ruleset
APIv3 Generate Security Cloud API Access Token CopyAPIv3 Generate SE API Access Token CopyCreate Firewall ConfigurationInternetbadguys - Demo Site
2-Orbital
Authorize with Token
1-Orbital Generate Token2-Orbital Check Status
Query Catalog entries
Get public stock query catalogueGet Organization catalog queries
Queries-3-Generate Queries-3a-Probe Endpoints
Probe Linux
Queries-3-Generate Queries-3b-StockQueries
Query by catalog ID: installed_programs_monitoring (Win)
Queries-4-Review Result
4-Orbital Job Status4-Orbital Show Result
Queries-5-Manage ORG
4-List WebhooksDelete Webhook
Scripts-Script Catalog entries
Get all catalog stock queriesGet Organization catalog scripts
Scripts-Get Script Details
Get Script Details by scriptID
Scripts-Script Live Execution
Live execution of a script - os:windows
3-Private Intelligence
1-Generate Bearer Token first
APIv3 Generate SecureX API Access Token
2-My Casebook
Create CasebookShows Casebook ContentDelete Casebook by ID
DemoData_CozyDuke_Casebook
Check: CozyDukeCreate: CozyDukeDelete: CozyDuke
Infos about observable
SHA256: get verdictsSHA256: get judgementsSHA256: get indicatorsIP: get verdictsIP: get judgementsIP: get indicatorsDomain: get verdictsDomain: get judgementsDomain: get indictors
List All CasebooksSearch Casebooks: all contentSearch Casebooks: title onlySearch Casebooks: descriptionCTIA: MetricsCTIA: PropertiesCTIA: StatusCTIA: Version
Introduction
1-Secure Endpoint
Initialize Variables
Initialize: Set Variables
Check Status
Check Status
APIv1 - queries-Audit Logs
All Audit Log TypesAudit Log Type - AllowList
APIv1 - queries-Computers
Search computer by name and store additional valuesSearch computer by IPSpecific computer by GUID Trajectory
APIv1 - queries-Computer Activity (Hunting)-Query for Sightings
Which computer reported URL (Demo data)
APIv1 - queries-Computer Activity (Hunting)-Investigate
Computer ObjectGroup ObjectComputer Trajectory
APIv1 - queries-Endpoint Isolation
Isolation feature availability for endpointIsolation status for endpointIsolation StartIsolation Stop
APIv1 - queries-Events and Event Types-Events Per Computer
Event Type: Behavioral Protection for specific computer
APIv1 - queries-Events and Event Types
All Event TypesComputer Events by SHA256
APIv1 - queries-File List
Show Application Blocking List by nameShow all Simple Custom Detection Lists by name
APIv1 - queries-Forensic Snapshot (Hunting)
List Forensic Snapshots for Computer
APIv1 - queries-Indicators (Hunting)
List all available indicators with Event Count
APIv1 - queries-Vulnerabilities (Hunting)
Vulnerable Applications by GroupGUIDOS Vulnerabilities per ComputerVulnerable Applications by SHA256 and Computers
APIv1 - queries-Compromise Inbox (Hunting)
Compromises - Inbox
APIv1 - queries-Manage ORG-Event Streams
List Event StreamsList Event Stream by ID
APIv1 - queries-Manage ORG-Webhooks
List WebhooksDelete Webhook by ID
APIv1 - queries-Deployment Packages
Create Deployment packageCreate Deployment package Copy
Use Cases-Create and Delete Groups demo
Refill Sub-Group GUID if missing4-Generate Sub-Group5-Move Sub-Group under Top Group6-Delete Top group by GUID7-Delete Sub-group by GUID
APIv3 - queries-1-Generate Bearer Token first
APIv3 Generate Security Cloud API Access TokenAPIv3 Generate SE API Access TokenAPIv3 Access Secure Endpoint API - multiple ORGs
APIv3 - queries-Exclusions
List Exclusion Set Entries - WindowsList Cisco Maintained ExlcusionsCreate Exclusion ListList Exclusion List Property by GUIDChange Exclusion List Property by GUID (Name)Delete Exclusion List
APIv3 - queries-Device Control-DVC: List all configurations
List Device Control Configurations - ALL
APIv3 - queries-Device Control-DVC: Check if configuration exists
DVC: Check BaseRule and update variableDVC: Check exception rule is already there
APIv3 - queries-Device Control-DVC: Add configuration and exeption rule
1-Add a DVC ConfigurationAdd DVC Rule to given DVC configurationList DVC Rulses for given DVC configuration
APIv3 - queries-Device Control-DVC: remove configuration
1a-Update DVC ConfigurationRemove a DVC exeption ruleRemove a DVC Configuration
APIv3 - queries-IOCs
List IOCs
APIv3 - queries-Policies
List all Policy Objects (Search Parameters)List all Policy Types (dynamic Visualizer)Delete Policy Object
APIv3 - queries-Uninstall the connector
Uninstall the connector
APIv3 - queries-Firewall-FW: List all configurations
List Host Firewall Configurations
APIv3 - queries-Firewall-FW Get Host Firewall Configuration Properties by GUID
Get Host Firewall Configuration Properties by GUID
APIv3 - queries-Firewall-FW: List Firewall Configuration Rules
List Firewall Configuratin Rules
APIv3 - queries-Firewall-FW: Get Firewall Rule Details
Get Firewall Rule Details
APIv3 - queries-Firewall-FW: Create/Rename/Delete Firewall Configuration
Create Firewall ConfigurationUpdate Firewall Configuration - Default Action BlockDelete Firewall Configuration
APIv3 - queries-Firewall-FW: Create/Delete Firewall Rule
Create Firewall RuleDelete Firewall Rule
APIv3 - queries-Firewall-FW: My personal FW Test Ruleset
APIv3 Generate Security Cloud API Access Token CopyAPIv3 Generate SE API Access Token CopyCreate Firewall ConfigurationInternetbadguys - Demo Site
2-Orbital
Authorize with Token
1-Orbital Generate Token2-Orbital Check Status
Query Catalog entries
Get public stock query catalogueGet Organization catalog queries
Queries-3-Generate Queries-3a-Probe Endpoints
Probe Linux
Queries-3-Generate Queries-3b-StockQueries
Query by catalog ID: installed_programs_monitoring (Win)
Queries-4-Review Result
4-Orbital Job Status4-Orbital Show Result
Queries-5-Manage ORG
4-List WebhooksDelete Webhook
Scripts-Script Catalog entries
Get all catalog stock queriesGet Organization catalog scripts
Scripts-Get Script Details
Get Script Details by scriptID
Scripts-Script Live Execution
Live execution of a script - os:windows
3-Private Intelligence
1-Generate Bearer Token first
APIv3 Generate SecureX API Access Token
2-My Casebook
Create CasebookShows Casebook ContentDelete Casebook by ID
DemoData_CozyDuke_Casebook
Check: CozyDukeCreate: CozyDukeDelete: CozyDuke
Infos about observable
SHA256: get verdictsSHA256: get judgementsSHA256: get indicatorsIP: get verdictsIP: get judgementsIP: get indicatorsDomain: get verdictsDomain: get judgementsDomain: get indictors
List All CasebooksSearch Casebooks: all contentSearch Casebooks: title onlySearch Casebooks: descriptionCTIA: MetricsCTIA: PropertiesCTIA: StatusCTIA: Version
Home1-Secure EndpointAPIv1 - queries-Forensic Snapshot (Hunting)

APIv1 - queries-Forensic Snapshot (Hunting)

Number of APIs: 1

  1. List Forensic Snapshots for Computer GET https://{{amp4e_APIhost}}/v1/forensic_snapshots?q={{amp4e_Connector_GUID}}

Related Documentation

  • 1-Secure Endpoint1 Secure Endpoint
  • Initialize VariablesInitialize Variables
  • Initialize VariablesInitialize: Set Variables
  • Check StatusCheck Status
  • Check StatusCheck Status
Previous
Show all Simple Custom Detection Lists by name
Next
List Forensic Snapshots for Computer
Cisco Secure Endpoint
Cisco Secure EndpointAPI Documentation
Claim this pageReport this pageAll Projects
Powered byQodex.ai