Secureworks Taegis XDR (Red Cloak TDR)
- 21 Sep 2023
- 2 Minutes to read
- Print
- DarkLight
- PDF
Secureworks Taegis XDR (Red Cloak TDR)
- Updated on 21 Sep 2023
- 2 Minutes to read
- Print
- DarkLight
- PDF
Article Summary
Share feedback
Thanks for sharing your feedback!
Secureworks Taegis XDR (formerly Red Cloak TDR) is an endpoint detection and response technology for the cloud, endpoints and the network.
Types of Assets Fetched
This adapter fetches the following types of assets:
- Devices
Parameters
- Client ID and Client Secret (required) - The credentials for an account that has the permissions to fetch assets.
- Verify SSL (required, default: false) - Select to verify the SSL certificate offered by the server. For more details, see SSL Trust & CA Settings.
- HTTPS Proxy (optional, default: empty) - A proxy to use when connecting to the server.
- If supplied, Axonius will utilize the proxy when connecting to the server.
- If not supplied, Axonius will connect directly to the server.
- HTTPS Proxy User Name (optional, default: empty) - The user name to use when connecting to the server via the value supplied in HTTPS Proxy.
- If supplied, Axonius will authenticate with this value when connecting to the value supplied in HTTPS Proxy.
- If not supplied, Axonius will not perform authentication when connecting to the value supplied in HTTPS Proxy.
- HTTPS Proxy Password (optional, default: empty) - The password to use when connecting to the server via the value supplied in HTTPS Proxy.
- If supplied, Axonius will authenticate with this value when connecting to the value supplied in HTTPS Proxy.
- If not supplied, Axonius will not perform authentication when connecting to the value supplied in HTTPS Proxy.
- Secureworks Region (optional, default: US1) - Select the region of your domain.
Region Identification
The following URLs are associated with each drop-down selection on the connection configuration panel:
- US1 - https://api.ctpx.secureworks.com
- US2 - https://api.delta.taegis.secureworks.com
- EU - https://api.echo.taegis.secureworks.com
- For details on the common adapter connection parameters and buttons, see Adding a New Adapter Connection.
Advanced Settings
Note:
Advanced settings can either apply for all connections for this adapter, or you can set different advanced settings and/or different scheduling for a specific connection, refer to Advanced Configuration for Adapters.
- Exclude IPs older than 24 hours (required, default: False) - Set this parameter to only add IP addresses if they were last seen in the last 24 hours. If there are no IP addresses seen in the last 24 hours, the single latest IP will be added, even if the last seen is older than 24 hours.
- Fetch DataSource data - Select this option to add the DataSource data to each asset, if available.
- Calculate Agent Health - Toggle on Calculate Agent Health to add a calculated agent health for the selected module to each device. You can select as many modules as required. The agents status will return one value in the agent status field of either ‘Healthy’ or ‘Unhealthy’. If even one module out of all modules selected reported unhealthy the agent status will report as ‘Unhealthy’.
APIs
Axonius uses the Red Cloak TDR GraphQL API.
Was this article helpful?