Secureworks Taegis XDR (Red Cloak TDR)
  • 21 Sep 2023
  • 2 Minutes to read
  • Dark
    Light
  • PDF

Secureworks Taegis XDR (Red Cloak TDR)

  • Dark
    Light
  • PDF

Article Summary

Secureworks Taegis XDR (formerly Red Cloak TDR) is an endpoint detection and response technology for the cloud, endpoints and the network.

Types of Assets Fetched

This adapter fetches the following types of assets:

  • Devices

Parameters

  1. Client ID and Client Secret (required) - The credentials for an account that has the permissions to fetch assets.
  2. Verify SSL (required, default: false) - Select to verify the SSL certificate offered by the server. For more details, see SSL Trust & CA Settings.
  3. HTTPS Proxy (optional, default: empty) - A proxy to use when connecting to the server.
    • If supplied, Axonius will utilize the proxy when connecting to the server.
    • If not supplied, Axonius will connect directly to the server.
  4. HTTPS Proxy User Name (optional, default: empty) - The user name to use when connecting to the server via the value supplied in HTTPS Proxy.
    • If supplied, Axonius will authenticate with this value when connecting to the value supplied in HTTPS Proxy.
    • If not supplied, Axonius will not perform authentication when connecting to the value supplied in HTTPS Proxy.
  5. HTTPS Proxy Password (optional, default: empty) - The password to use when connecting to the server via the value supplied in HTTPS Proxy.
    • If supplied, Axonius will authenticate with this value when connecting to the value supplied in HTTPS Proxy.
    • If not supplied, Axonius will not perform authentication when connecting to the value supplied in HTTPS Proxy.
  6. Secureworks Region (optional, default: US1) - Select the region of your domain.
Region Identification

The following URLs are associated with each drop-down selection on the connection configuration panel:

  • US1 - https://api.ctpx.secureworks.com
  • US2 - https://api.delta.taegis.secureworks.com
  • EU - https://api.echo.taegis.secureworks.com
  1. For details on the common adapter connection parameters and buttons, see Adding a New Adapter Connection.

SecureworksTaegis XDR


Advanced Settings

Note:

Advanced settings can either apply for all connections for this adapter, or you can set different advanced settings and/or different scheduling for a specific connection, refer to ​Advanced Configuration for Adapters.

  1. Exclude IPs older than 24 hours (required, default: False) - Set this parameter to only add IP addresses if they were last seen in the last 24 hours. If there are no IP addresses seen in the last 24 hours, the single latest IP will be added, even if the last seen is older than 24 hours.
  2. Fetch DataSource data - Select this option to add the DataSource data to each asset, if available.
  3. Calculate Agent Health - Toggle on Calculate Agent Health to add a calculated agent health for the selected module to each device. You can select as many modules as required. The agents status will return one value in the agent status field of either ‘Healthy’ or ‘Unhealthy’. If even one module out of all modules selected reported unhealthy the agent status will report as ‘Unhealthy’.

TaegisModuelSettings


APIs

Axonius uses the Red Cloak TDR GraphQL API.


Was this article helpful?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.