Endpoint Security (HX) appliance capabilities and authorized local roles

Prev Next

On an Endpoint Security (HX) appliance, roles have associated capabilities. The functionality provided by each capability and the roles authorized to perform each capability are described in the following table.

In general, if a user is assigned an AAA role that has Web UI access, the actions they can perform occur mostly in the Web UI. In the CLI, only the show commands are available for these roles. The exceptions to this are the admin role (which can perform all available functions in the CLI) and the operator role (which can perform HX appliance software maintenance functions in the CLI, but cannot run CLI commands related to HX Series configuration settings).

If a user is assigned an AAA role that has API access, the actions they can perform occur only in the API. The only exception to this is the fe_services user, who can perform all available functions in the CLI and API, but has no access to the Web UI.

Capability

Description

Authorized AAA roles

Web UI Access

Access the Web UI.

Users with auditor roles have access to logs only.

Users with monitor roles have access to the Appliance Settings and Health Check, and are able to view Appliance Updates only.

admin

analyst

analyst_sr

auditor

investigator

monitor

operator

API Access

Access the API

api_admin

api_analyst

fe_services

CLI Access

Access the CLI

admin (full access)

analyst (show commands only)

analyst_sr (show commands only)

auditor (show commands only)

fe_services (full access)

investigator (show commands only)

monitor (show commands only)

operator (appliance image management, show commands only)

FireEye as a Service (FaaS)

Manage services

fe_services

Acquisitions (view)

View acquisitions

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

Agent Clone

Manage cloned agents

admin

Agent Clone (view)

View cloned agents

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

operator

Agent Configurations

Manage agent configuration settings and deploy them to the agents

admin (Web UI)

api_admin (API)

operator (Web UI partial)

Agent Diagnostics

Perform agent diagnostics

admin

fe_services

Agent Diagnostics (view)

View agent diagnostics

admin

fe_services

Alerts

Manage and view alerts

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

Approve Containment

Approve containment requests and stop containment of host endpoints

admin

api_admin

fe_services

investigator

Audit Viewer

Request and view audit data.

In the Web UI, this includes processing acquisition data and reviewing it in the Audit Viewer, In the API, this involves searching for audit data in acquisitions using a script.

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

Authentication (AAA)

Maintain authorization settings for user accounts

admin

fe_services

Authentication (AAA) (view)

View authorization settings for user accounts

admin

monitor

operator

Dashboard

Select links on the Web UI dashboard

admin

analyst

analyst_sr

investigator

Dashboard (view)

View the Web UI dashboard

admin

analyst

analyst_sr

investigator

operator

Data Acquisitions

(Live Response)

Request data acquisitions

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

Enterprise Search

Run enterprise searches

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

File Acquisitions

Request file acquisitions

admin

analyst_sr

api_admin

api_analyst

fe_services

investigator

Health Check View

Review system health

admin

analyst

analyst_sr

fe_services

investigator

monitor

operator

Hosts

Maintain host lists

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

Hosts (view)

View host lists

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

operator

Host Sets

Maintain host sets

admin

operator

Host Sets (view)

View host sets

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

operator

Indicator

Maintain and view indicators and custom indicators

admin

analyst

analyst_sr

api_admin

api_analyst

fe_services

investigator

Module Administration

Install, uninstall, enable, disable, and upgrade modules

admin

api_admin

investigator

Module Data

View module data pages

all roles

Appliance Licenses

Maintain appliance licenses

admin

fe_services

operator

Appliance Licenses (view)

View appliance licenses

admin

fe_services

monitor

operator

Logs

View logs and customize log settings

admin

auditor

fe_services

operator

Manage Own Account

Change the password for the specific user account

admin

analyst

analyst_sr

auditor

investigator

monitor

operator

Network

Maintain network settings

admin

operator

Network (View)

View network settings

admin

fe_services

monitor

operator

PKI

Import and export HX certificates for the agent population

admin

Stats

Manage statistics

admin

operator

Stats (view)

View statistics

admin

fe_services

monitor

operator

Appliance Settings (general)

Perform general system administration functions for the appliance (but not sensitive functions). These include setting the date and time, modifying DTI network settings, managing notifications, modifying network settings, changing certificates and keys, managing appliance licenses, and changing the login banner.

admin

operator

Appliance Settings (view)

View appliance settings.

admin

fe_services

monitor

operator

Appliance Settings (sensitive)

Perform general and sensitive administrative functions for the appliance. These include managing user accounts (AAA) and appliance backup and restore functionality.

admin

fe_services

System Diagnostics

Perform system diagnostics

admin

operator