containment Audit

Prev Next

Contains or stops containment of host endpoints.

This audit cannot be imported into a data acquisition script. See Audits That Cannot Be Imported on page 1.

Supported Platforms

Supported for all platforms. Windows, Linux and macOS

Input Parameters

The following input parameters are available for this audit. Some parameters are supported only in Windows environments.

Type

Details

Values

Description

Platform

All

Windows, Linux, and macOS environments.

Format

String

Valid values are a string of text.

Required?

yes

This parameter is required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

"contain"

"uncontain"

Specify "contain" to contain the host endpoint or "uncontain" to release the host endpoint from containment.

Version

Details

Values

Description

Platform

All

Windows, Linux, and macOS environments.

Format

String

Valid values are a string of text.

Required?

yes

This parameter is required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Specify the version of the agent you are containing.

Platform

Details

Values

Description

Platform

All

Windows, Linux, and macOS environments.

Format

String

Valid values are a string of text.

Required?

yes

This parameter is required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

"win32"

"win64”

Specify the Windows platform on which you are containing the agent.

HashAlgorithm

Details

Values

Description

Platform

All

Windows, Linux, and macOS environments.

Format

String

Valid values are a string of text.

Required?

yes

This parameter is required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

"md5"

"sha1"

"sha256"

"sha384"

"sha512"

Specify the algorithm used for hashing.

HashValue

Details

Values

Description

Platform

All

Windows, Linux, and macOS environments.

Format

String

Valid values are a string of text.

Required?

yes

This parameter is required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

The hash value of the containment driver.

Location

Details

Values

Description

Platform

All

Windows, Linux, and macOS environments.

Format

String

Valid values are a string of text.

Required?

yes

This parameter is required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

The URL where the containment driver can be found.

Length

Details

Values

Description

Platform

All

Windows, Linux, and macOS environments.

Format

ByteSize

Valid values are specified in bytes.

Required?

yes

This parameter is required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Specify the size of the containment driver, in bytes.

Whitelist

Details

Values

Description

Platform

All

Windows, Linux, and macOS environments.

Format

ArrayOfString

Valid values are specified in an array of string values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Specify the containment whitelist.