Secureworks Taegis XDR (Red Cloak TDR)
  • 07 Oct 2024
  • 2 Minutes to read
  • Dark
    Light
  • PDF

Secureworks Taegis XDR (Red Cloak TDR)

  • Dark
    Light
  • PDF

Article summary

Secureworks Taegis XDR (formerly Red Cloak TDR) is an endpoint detection and response technology for the cloud, endpoints and the network.

Related Enforcement Actions:

Types of Assets Fetched

This adapter fetches the following types of assets:

  • Devices

Parameters

  1. Client ID and Client Secret (required) - The credentials for an account that has the permissions to fetch assets.

  2. Verify SSL - Select whether to verify the SSL certificate of the server against the CA database inside of Axonius. For more details, see SSL Trust & CA Settings.

  3. HTTPS Proxy (optional) - Connect the adapter to a proxy instead of directly connecting it to the domain.

  4. HTTPS Proxy User Name (optional) - The user name to use when connecting to the value supplied in Host Name or IP Address via the value supplied in HTTPS Proxy.

  5. HTTPS Proxy Password (optional) - The password to use when connecting to the server using the HTTPS Proxy.

  6. Secureworks Region (optional, default: US1) - Select the region of your domain.

    Region Identification

    The following URLs are associated with each drop-down selection on the connection configuration panel:

    • US1 - https://api.ctpx.secureworks.com
    • US2 - https://api.delta.taegis.secureworks.com
    • EU - https://api.echo.taegis.secureworks.com

To learn more about common adapter connection parameters and buttons, see Adding a New Adapter Connection.

SecureworksTaegis XDR


Advanced Settings

Note:

Advanced settings can either apply for all connections for this adapter, or you can set different advanced settings and/or different scheduling for a specific connection, refer to ​Advanced Configuration for Adapters.

  1. Exclude IPs older than 24 hours (required, default: False) - Set this parameter to only add IP addresses if they were last seen in the last 24 hours. If there are no IP addresses seen in the last 24 hours, the single latest IP will be added, even if the last seen is older than 24 hours.
  2. Fetch DataSource data - Select this option to add the DataSource data to each asset, if available.
  3. Filter Assets by Asset State (default: All) - You can filter assets by choosing the asset state value. From the dropdown, select one or more asset state values.
  4. Calculate Agent Health - Toggle on Calculate Agent Health to add a calculated agent health for the selected module to each device. You can select as many modules as required. The agents status will return one value in the agent status field of either ‘Healthy’ or ‘Unhealthy’. If even one module out of all modules selected reported unhealthy the agent status will report as ‘Unhealthy’.

TaegisModuelSettings

  1. Filter by tags - Enter a comma-separated list of tags to filter devices during fetch.

APIs

Axonius uses the Secureworks Taegis XDR Assets GraphQL API.


Was this article helpful?