TomML
Level 1
Level 1
Member since ‎11-18-2022
Online

User Statistics

  • 20 Posts
  • 0 Solutions
  • 1 Helpful votes Given
  • 3 Helpful votes Received
Recent Badges
20 Discussion Posts
5 Discussion Posts
First Discussion
First Question
10 Discussion Posts
1 Reply
10 Replies
5 Replies
1 Helpful Vote
FirstQuestion

User Activity

Is there any additional documentation (blogs, webinars, etc) beyond Microsoft Windows Endpoint Target (cisco.com) on how to set up a Windows Endpoint target in XDR?  Is it possible to target internal endpoints?  I am under the impression that it woul...
The HTTP Request fails when trying to query our secure email appliance using the subjectfilterValue parameter of a subject that contains an &, i.e subject is "Foo & Bar."   /sma/api/v2.0/message-tracking/messages?searchOption=messages&ciscoHost=All_H...
Hi, within XDR I can conduct message remediation by pivoting off of a Cisco Message ID (MID):However I cannot seem to find any documentation detailing how to conduct message remediation with the API (PUT or POST with a list of MIDs) so I can incorpor...
Curious if there is way to mark a potential compromise as resolved with the API.  I would like to automate some known false positives that routinely appear.I didn't notice any POSTs in the current version of the documentation (Secure Endpoint API - C...
Is there a way to safelist or create an exclusion for this benign powershell command without safelisting cmd.exe or powerhell.exe - just the actual Command parameter?  These events are classified as "Command Obfuscation With Symbols" compromises and ...
Community Statistics
Member Since ‎11-18-2022 08:11 AM
Date Last Visited ‎10-10-2024 01:56 PM
Posts 20
Total Helpful Votes Received 3
Helpful Votes From
Helpful Votes Given To