Collects indicator of compromise (IOC) matches from host endpoints.
This audit cannot be imported into a data acquisition script. See Audits That Cannot Be Imported on page 1.
Supported Platforms
Windows, Linux and macOS
Input Parameters
The following input parameters are available for this audit.
LastSeenID
Details | Values | Description |
|---|---|---|
Platform | Windows and macOS | Windows and macOS environments |
Format | Numeric | Valid values are numeric. |
Required? | no | This parameter is not required. |
Repeatable? | no | This parameter can be specified only once per audit request. It cannot be repeated. |
Valid Values | Specify the ID of the last match that was sent. Use this parameter to avoid sending the same matches every time this audit is run. If this parameter is not included in the audit, all matches are returned. |