Create a capability profile for the FireEye Endpoint integration
Create a profile and select the FireEye HX capabilities that you want the profile to run.
Before you begin
Role required: NowPlatform Security incident administrator (sn_si.admin)
About this task
Profiles are created to club capabilities together, and would help Analysts perform the investigation/remediation easily.
- Get Host Details
- Get Logged On Users
- Get Network Statistics
- Get Running Processes
- Get Running Services
- Get File
- Isolate Host
- Remove Isolation
You cannot club Get File, Isolate Host, and Remove Host Isolation capabilities with other capabilities while creating a profile. Profiles for these have to be individually created. On the other hand, Get System Details, Get Logged on Users, Get Network Stats, Get Running Processes, and Get Running Services can be clubbed together. You could create profiles individually or by clubbing them in full or parts as per your need. Once a capability is included in a profile, it cannot be included in another profile.
To create a new capability profile, follow these steps: