Interact with Attivo BOTsink
Supported Actions
- test connectivity: Validate the asset configuration for connectivity using supplied configuration
- on poll: Ingest alerts from the Attivo BOTsink
- get events: Pull Attivo events based on source IP and timeframe
- check user: Verify whether a user is Deceptive
- check host: Verify whether a host is Deceptive
- list hosts: List all deceptive hosts (network decoys) on the Attivo BOTsink
- list users: List all deceptive users on the Attivo BOTsink
- list playbooks: List all configured playbooks on the Attivo BOTsink
- run playbook: Run a preconfigured Playbook on the Attivo BOTsink
- deploy decoy: Bring up a network decoy system